What makes it so that users coming through Tor or proxies get the captcha, but they don't get it when connecting without using a proxy?
A config option, somewhere deep down. A good idea, since IME practically all these visitors are suspicious/malicious people, or bots

I just don't buy this "civil liberties" stuff. As a forum admin (not this one : ) I can tell you that malicious people are very obvious, TOR or not - because almost nobody uses TOR.
Using Cloudflare requires the operator of an HTTPS site to share their certificate with Cloudflare, or to use Cloudflare's certificate.
Normally you use CF's certificate - this is a
huge advantage of using CF because it avoids all the crap with cron jobs to renew them (today's another absolutely stupid fashion is to use short-lived certs, and yes I know the supposed reasons, but they are BS for a web server cert) which tend to break after a year or two and then you need to pay somebody 1k/day to fix it, because the original coder has moved on... A small company is always held to ransom by this stuff.
I have reason to believe that Cloudflare has been involved not only in gathering data from secured connections, but they have actually been modifying the content delivered to clients in some cases, such as to deliver state sponsored malware to certain clients.
I don't believe that for a moment.
Anyway, they would only see the stuff the client is browsing anyway

BTW, if moving to CF you should firewall your server to accept 80 and 443 connections only from CF IPs. There is a website out there which maintains an archive of all IPs which had a DNS published and if you ran your website for even hours without CF, that IP will be stored for ever and if somebody wants to hit your server directly, they can do.