How does pdns-recursor stack up against unbound chained with dnscrypt-proxy?
With the proxy you're still trusting a third party with all your DNS data, with a recursor that's not the case.
All the DNS plaintext is being passively tapped on the wire anyways. At least with a local resolver you're not also actively shoveling it all to a remote third party recursion service.