Yes. Reverse proxies need to own the private key which belongs to the FQDNs certificate for the TLS connection between rproxy and browser. Also, sometimes HTTP Headers need to be rewritten.
As a result there is no end to end encryption between the server and the browser. You need to trust cloudflare as you need to trust your hoster.