Everyday people who are worried about state-actor threats - an incredibly targeted and unlikely scenario for the average person - but are less concerned about their personal information being harvested for marketing purposes - something that happens all the time to everyone.
Even if the foreign government spies more nether jurisdiction is likely to care enough about you specifically to make an international case of it.
In other words I'd think most Americans would be better off proxying through Europe, and most Europeans would be better off proxying through the US.
Even better would be to proxy through a third country that your own country is unlikely to cooperate with, and which won't care about you personally.
E.g. I wouldn't want to live in Iran or North Korea, but I'd think proxying DNS through them would in some way maximize my privacy if I was living in Europe or the US.
I'll never travel to either of them, and my authorities are vanishingly unlikely to cooperate with either of them for anything short of murder.
I agree with you that people should be more worried about companies collecting their personal info, but we know now that the state collecting your data isn't incredibly targeted or at all unlikely. They just take everything. It's happening to every last one of us every single day. It's been going on for decades.
https://en.wikipedia.org/wiki/Room_641A https://en.wikipedia.org/wiki/Russ_Tice
And if I was an intelligence agency trying place spies, Cloudflare would be among the first tech companies I'd target.
This feature seems almost exclusively a feature for people in the ISP-monopoly-friendly United States.
This seems like a threat model swap in the conversation. The subject threat model here is (1) defending against companies stealing and selling my data. You swapped in the threat of (2) state level agencies spying on you through these companies.
The problem is that #2 seems to be an intractable problem. (but not so much because of an infiltrated DNS provider, more like cable taps and infiltrated hardware manufacturers)
#1 seems to be a more solvable problem (albeit at increasing levels of complexity). When you bring #2 into the conversation, it defocuses on the solution to #1 and gets to a point where we all throw up our hands and admit helplessness and defeat.
I see this happen often and I think every conversation should be clearly grounded in the threat model that is being addressed.