Apologies in advance if I get this wrong.
What it sounds like is building the equivalent of an xpriv.
Youβd probably need some sort of offline signing device to do this like the Bitcoin wallets institute. The master key needs to live βsomewhereβ.
On the web clients the NIP-07 carry the nsec and only takes in data to sign, never exposing the private key.
Iβm not an iOS expert and donβt know how youβd do this with a native app.