Fair point, but that's an argument for NIP-46, not local nsec storage.
If Amber isn't accessible to Google Play users, it seems to me the solution is a signing flow that doesn't require it—but still retains the option for users who can sideload, at least for now.
Not putting the key directly in the client.
A user who can't install Amber probably shouldn't be managing a raw nsec either.
@greenart7c3 any plans to bring Amber to Google Play?