The TAPSIGNER encrypts the XPRV with AES using a 16-byte key printed on the back of the card. The backup file plus the key lets you recover the XPRV.
I think Nunchuk only keeps a backup of the encrypted XPRV provided by the tapsigner at setup time... They have no idea what the decryption key is.
this would start to make sense... thankyou for explaining (Nunchuk should do the same!)