They are far more than just http forwarding, it's data collection for DDoS primarily, but there are risks and issues. At the end of the day what does privacy even mean if a single provider sees so much. Regarding the IPs, here it's hitting them up on the initial client coordination, and then yes, it can tunnel direct without seeing CF. But there are risks of timing here.
Please see this article for in general the issues with CF:
https://simplifiedprivacy.com/why-and-what-is-arweb/arweave-website-creator.html