I don't consider corporate IT or Starbucks to be trustable.
AWS I would "trust" slightly more only because I get to implement the infrastructure and among the sea of trillions of requests they serve it would be a bit more of a challenge for them to figure out which of those requests are VPN browsing data and clean that data. I can also mildly obfuscate and pollute requests using their own infrastructure and make it hard for them to extract anything meaningful about me unless they really wanted to.
Basically AWS isn't already set up as a VPN service, so they'd have to put in a nonzero amount of time to extract, parse, collate, and analyze VPN logs, let alone figure out which instances among their billions are actually VPN instances, especially if I run a non-standard, modified protocol. Unless I was some Snowden-like target it's unlikely they would waste a couple weeks of engineer hours to wireshark and clean the data from my instances.
Mullvad on the other hand handles 100% VPN browsing data so if they unscrupulously keep logs, they would have clean logs to begin with, nicely organized by username, which is scary. They wrote the client and they control the protocol. They also rent their instances from various providers (the names of which they disclose on their website) and I could presumably just bypass them and rent an instance with one of those providers directly.