I store all of my data in Nextcloud hosted on a VPS. It's virtually impossible to guarantee the security of data on a running VPS, so my sensitive data is also encrypted with Cryptomator, so I don't have to trust my VPS host (but I also chose my VPS host carefully with data privacy and security as my main criteria). My host makes daily backups of the VPS off-site, and I also backup my Nextcloud data directory daily to Tardigrade/Storj DCS via their s3 API using Restic. An advantage of Storj DCS is that it's geographically distributed, so you're insulated from natural disasters. I also sync all of my Nextcloud data to both of my laptops, and use Restic to make another backup snapshot on an external USB SSD once a month. My Docker configs for Nextcloud are stored on GitHub, but I wouldn't have trouble recreating them if I somehow lost them.
For my own personal risk model, I think my sensitive data is pretty well protected from third parties, and I think all of my data is reliably backed up accounting for multiple types of failure. My biggest vulnerability is probably my password manager, where all of my encryption keys and passwords are stored.
If anyone has any suggestions on how I can improve my setup, or any potential problems you see, I'd love it if you share!