Thanks for the comments. I agree on the general consensus, that once an encryption key enters the VPS, the encryption is compromised.
However, I'm thinking more in practical terms, eg. the service provider doing just casual scanning across all disks of VPS instances. Some examples could be: cloud authentication keys, torrc files, specific installed software, SSH private keys, TLS certificates.
I use Debian stable because I'm tired of constantly twiddling with breaking stuff, I just want a distro that keeps working without issues and tinkering.
If you still want to learn Linux stuff and debug packages, then go for a bleeding edge distro.
I sent email to oxenfree@nightschoolstudio.com and told them in no uncertain words that what they are doing is illegal, and asked how they are going to fix the situation.
If I can find time to, I'll see about contacting the local consumer protection organisation.
Could you edit the post and add the actual store links? Thanks!