If I were from NSA:
1. Go to linode (or your favourite hosting provider).
2. Make a snapshot of memory of a running VM.
3. Extract encryption keys from that snapshot.
4. Decrypt.
The message here is: it does not matter which server setup you use, be it own hardware, cloud hosting or gmail. If data is seen unencrypted in any place which is not under exclusive control of yourself or your peers, it can (and eventually will) be intercepted.