I love this idea, but my two "deal breaker" worries are: (a) data backup, and (b) security. I hate that this is the case, but when comparing a "box-at-home" vs. a "corporate-run service", the corporate-run service is less likely to lose my data and more likely to apply security patches and updates ASAP. Even with 0days and all of the "hackers stole millions of users' data" posts, think the point remains strong; altho…
There's no reason why this system couldn't use duplicity with a password to back up to S3 or a similar service.
Since it's just a Debian package, it could use the standard Debian automated-update system to handle security.