Your missing the point:
> at no point prior is data sent visible
Because this is not true for the browser having the app or game running.
If I simply copy the link from the inspector, and paste it in my adress bar (with or without altered values) my transmission goes through ... and IF that link is using https ... it will also go over https
https is security between user <--> host
But in this scenario, the user is a potential culprit .. (for example, wanting to cheat with the biggest highscore)
Sorry, I hit the reply button to early. See edit in post above