It's "well known"? News to me.
I doubt the NSA has storage space for even 1 year's worth of "most of encrypted Internet traffic", much less for permanently storing it.
Having the private key of the root cert does not allow you to decrypt traffic either.
Even if you have your own rack at a colocation, you could argue that if you don't have full disk encryption someone could simply copy your disk.
I am just trying to be practical. If someone is intent on reading what users specifically send me, they can probably find bad hygiene on my part and get it but my concern is they should not be able to do this wholesale at scale for everyone.
You can have full-disk encryption then. It can still possibly be compromised using more advanced methods like cold boot attacks but they are relatively involved, and is very detectable in the form of causing downtime.