Thank you @jdrch that was a very fine and helpful solution.
I know it is not a backup, I would do this from my little server setup. (I already was doing this with my seafile setup with which I want to replace this).
Okay good point about just using full disk encryption, gotta finally look into LUKS I guess. But even then, the disk is only en-or decrypted after mounting/unmounting, right? So a running system has decrypted its disk already and the files are thus accesible. It is not encrypt-on-write, is it? (Maybe that does not even exist, sorry for my newbieness)