You're right, I could use Cloudflare's app but I would loose the ad blocking.
By default, the pihole-template container was configured to use Cloudflare's DNS as an upstream but the connection from Pi-hole to the upstream is not using DoH. I get that the connection from my phone to your container is using DoH, but are all of the queries from your container (whether its pointed to Pi-hole or the default Cloudflare and Google upstreams) also using DoH?
The way I have it set up now, I get a DoH connection from phone to your container and get the benefit of blocking ads as well. Then I get a different DoH connection to Cloudflare for all of the lookups coming from Pi-hole.