There's no reason the setup has to be any more complicated - it could work exactly as it does currently, only with the option of pointing it at your own server, instead of Amazon's, or even keep using Amazon's server, but end-to-end encrypt the data, with only you possessing the key.
Amazon and others know this. They don't offer it on purpose, because they want to retain control and a new revenue stream.