one addition I want to make to this:
user two-factor password and app salts
this would allow you to add a two factor to your private data, associated with a specific app.
if your key leaks you wouldn't get mass decryption of private notes.
nostr:note1g8epn75k0lctmr0h6vj2uw6r7dt54n6c4tlaa348a23gt34h2k4stctxmq