You are correct, your nsec is the one you need to keep private. However, you also need to enter your nsec in any mobile app, or web based clients like coracle or primal web to be able to make posts. So, you have to trust the website or app with your nsec. You'll be fine using your nsec with primal,...