Vanadium is built specifically for security. It lacks privacy features such as an ad blocker
Currently I use the AdGuard DoH server. It's not perfect, but I don't do a lot of browsing on my phone. There were some plans to implement this in vanadium https://github.com/GrapheneOS/Vanadium/issues/10
Basically the same thing.
Encrypted DNS is not for privacy, it is for stopping someone from altering your queries basically, because normal DNS is not encrypted. Domains are exposed through other various methods we explain. Please see our website where we've gone to the effort to explain this https://www.privacyguides.org/en/advanced/dns-overview/ we have a flow chart that characterizes the above methods of obtaining the domains you're requesting.