cloudflare is a proxy, while the computer have access to your data, it doesn't store it. They have compliance rules to follow and audits, to make sure that a credit card number is not stolen in transit in cloudflare. Even a hacker inside cloudflare would have problems to access the info, exactly because they are required to make it hard to access that info. I'm excluding 3 letters agencies demanding the info in a secret way, as that can happen in any place (and for sure they can fake certificates to act as a hidden proxy if needed, as the USA control many CA)
the keys/mouse, of course it is stats about it, what you are typing or where you click do not really matter for this, what matter is the movement speed, direction, we all make small mouse corrections during movement... in keyboard, the speed how you type, the time between keys, how long you take to press enter (submit or not), if you use delete/backspace, Caps, punctuation, etc if you press shift, ctrl, alt, meta, etc. What you type is already in the payload and don't really matter, the stats about how it was produced is what matter
Finally, i do agree that the traffic should be private, that is why we all use https... but bots, ai and attacks make it hard, so site owners agree in to having a middle men that helps filter the bad traffic and that can see the traffic. Cloudflare works because people trust them, and they until now, they didn't broke that trust that they are doing bad things with the traffic data... the day they break that trust, many people will stop using it for sure.
So if the site owner is ok in to having a middle men in their connections, it is mostly the same as not having it (you also do not know if the site side is using any cloud service, that is also a proxy, sending data between partners internally or have a hacker inside their network, seeing all traffic)