It doesn't matter.
Why? Because when going through the exercise of identifying risks in the system one can't assume the actors are benevolent and won't ever use the access+data they have for evil.
That's not at all to say all actors are evil and will always do the most harm possible. Many risks are never exploited in practice. But that doesn't mean the risk doesn't exist. It still does! And it might be exploited in the future (with companies, all it takes is a reorg that puts someone less ethical in charge).
Thus, when doing your threat modeling exercise, for the purposes of identifying risk, assume the various actors could do as much damage as they possibly could with the access they have.
So concretely, when I evaluate risk on google vs. DDG: I won't take into consideration any "privacy respecting" marketing, that's not important. What matters is how much damage can each party do, which one is less risky?
Both get my search queries which is inevitable for a search engine. So there's that risk but it's a wash.
But google has its tendrils woven into far more points from which they can and will correlate data. Google analytics, AMP, gmail/gsuite, chrome (for people using that), also most people have an active login session with google most of the time, etc.
DDG has a much smaller footprint on the internet from which to correlate data.
Therefore, even assuming both parties are equally evil, DDG presents a smaller risk.