@aeva your replies assume the wrong threat model, a state that actually wants to observe *you*, a target with a value so high that it is sensible to use their best 0-days and risk them being detected and published.
They only go for the big platforms because that is low-effort and the platforms are willing participants, so the most you need in contingency plans is a domain name you control (so you can move the server without too much disruption) and distributed backups (but that's good practice anyway).