Doesn't compute !
Even more so as the OP chose Cloudflare ! US Jursisdiction + Commercial Company ?
Or, wait until ODoH goes mainstream: https://datatracker.ietf.org/doc/html/draft-pauly-dprive-obl...
Well, if you're going to go to the trouble of building and running your own VMs or docker images then the obvious recommendation is to run your own recursive resolver (Unbound or Knot Resolver).
The added bonus is that CDN content will operate as expected for your IP range instead of you talking to the CDN server nearest to whatever datacentre you spoke to the third-party DNS BGP anycast on. This may or may not be a big deal depending on your geographic location and internet connection. I am aware some third-party DNS services have options to try to fix the CDN problem, but YMMV as to whether this works in practice.
Otherwise, if I was forced to name a third-party, I would likely name Quad9. Especially after their recent relocation to Swiss jurisdiction[1]. IIRC (its been a while since I read it) their privacy policy is also better than Cloudflare's too (e.g. no weird, "we'll retain some stuff for 25 hours" IIRC).
[1] https://www.quad9.net/news/blog/quad9-public-domain-name-ser...
I run my own resolving nameserver (unbound) on a server in a datacenter (but could be DO or EC2 or whatever).
The upstream for my nameserver is the DNS I set up for myself at nextdns.io which is ad-filtered like a pi-hole.
So I use my own DNS server and distribute that address to whomever or whatever needs it - and I control the traffic and usage and monitoring of it - but I also get ad-filtering without having to run a pi-hole.
Recommended.