Also specifically, my cloud proxy is a dump stream forwarder, it does not terminate SSL traffic. It stores no certificates. I didn't want it to leak anything in the case it was compromised. It's purpose is literally to hide my IP address, and offer a buffer layer if something should happen to it.
HSTS should protect my users in the case it gets compromised and the cert changes.