Fair point, but that's an argument for NIP-46, not local nsec storage.
If Amber isn't accessible to Google Play users, it seems to me the solution is a signing flow that doesn't require itβbut still retains the option for users who can sideload, at least for now.
Not putting the key directly in ...