Yes, you are just trusting them. There are apps or clients that keep your nsec private when creating an account or signing an event. I'm sure someone will suggest one.