Tricky question. I'm the chairman of Quad9's board of directors. So _I_ trust the organization. But I'd urge everyone else not to trust _any_ organization, but instead to do as much to protect yourself as possible, using an external recursive resolver only when you need to.
That means running your own caching resolver, with a local copy of the root zone and QNAME minimization enabled, and then using DNS-over-TLS to forward the minimum necessary query onward.
The next question then becomes whether to perform recursion yourself (by talking directly with authoritative nameservers) or to have Quad9 or another recursive server perform the recursion for you. Authoritative nameservers don't yet support transport encryption, though we're working very hard to support it on the 500 TLDs PCH is authoritative for, and Verisign is working very hard to support it on .COM and .NET. So that means that your traffic is subject to interception, and essentially all authoritative servers either log queries or have people logging queries off the wire in front of them. And if you're handling your own recursion, everything you don't have cached crosses the wire, and none of it is blended together with anyone else's traffic.
To make the decision as to whether it's better to trust a recursive or send queries directly, knowing something about the practices and purpose of the recursive is necessary. Quad9 is the only major recursive that's a public-benefit not-for-profit. There are other small ones which are not-for-profits (like the Taiwanese 101.101.101.101, operated by TWNIC), but all of the others that come near Quad9's scale or traffic are for-profit, operated by companies that monetize data. Quad9 and Cisco's commercial Umbrella service are the only two which are GDPR-compliant and thus legal to provide to European citizens.
Quad9 exists solely so that bad choices won't be the only choices.
-Bill Woodcock
Chairman of the Board of Directors
Quad9
[0]: https://www.quad9.net