If you think it matters where the data is stored (which shouldn't matter because it should be client side encrypted), running your own server would also be a risk. Because you cannot possibly have the same resources to monitor your server/router for suspicious activity...
Maybe I do, maybe I don't want my passwords to be at the same target as others, maybe I don't trust the hosting provider or Bitwarden the company (which you could argue, then I shouldn't trust the software, but I can monitor its behavior).
If you think it matters where the data is stored (which shouldn't matter because it should be client side encrypted), running your own server would also be a risk. Because you cannot possibly have the same resources to monitor your server/router for suspicious activity...