Cloudron does not set the CSP header unless a custom one is specified in the app configure view in the security page.
However apps may set this on their own, either through headers or also as meta tags in the delivered pages. Cloudron does not interfere here. This is however a topic for each app which is not setting those according to your needs.