the backup wouldn’t be encrypted but you can use luks to encrypt the backup drive too, the same way as you’d do with a drive in your computer.
i use rsync to send off my /home to an encrypted backup drive and restoring it you just reverse the source and destination and copy the stuff back.


iOS has their own attestation/anti-tamper api similar to google’s integrity api so that’s going to be used instead. the only difference is that on iOS you’ll need to download extra software specifically for this.
graphene devs said you can do it with their sandboxed version of gms but as far as i know that still involves having an account and handing over all your personal info to google.