There's one field in the app's request that's still unknown.
It's a header of seemingly encrypted data, along with a varying number of encrypted blocks (all the same length).
In those blocks could be anything, detailed gps co-ords, device details, there's a fair chance they can ban all these API users at the push of a button based on whatever's in those blocks.
Everything else is unencrypted - sent back and forth using the protobuf format, the formatting of the protobuf's were dropped on pastebin a few weeks ago.