Both of them you have to trust to do the right thing and that is an exercise left to the individual thinking of using either service. So lets not pretend that CloudFlare is a special case.
If you need to trust the none of your service providers can MITM your site then you can't use any PaaS or CDN, you need to terminate the SSL yourself, that includes for all static assets you use. No more jQuery from Google CDN, no more analytics/exception tracking/fonts from your favoured provider and no more advertising conversion tracking.
But then do also remember that it's possible for any web host to take over their customers site as long as they own the IP address. They just point the IP to another server, configure it to respond to the hostname and they can then even use any SSL certificate provider who validates the domain name with a file at a specific URL to grab a certificate.
Everyone has to make their own judgment on who they can trust. CloudFlare is no different.