This separates who sees what. Cloudflare (or any OHTTP gateway) sees who talks to who, but can't see the content. The service sees the content but not who you are/your IP.
You can imagine a lot of threat models where who you talk to isn't sensitive, nor is "someone talked to them about X" but knowing both facts is a risk.
For a single transaction that's great. The problem is whene a large fraction of the internet is served by a single entity (say cloudflare), then that entity has information about what sites/customers were visited by a specific ip address, and which ip addresses visited a certain site/customer.
Although, that is still better than them having the source ip and the content.