I'm not a pro in security but if you use a valid certificate with a certain domain name (not just a ip), it should be impossible to watch with a proxy in the middle? unless you cheat the certificate which are in the phone maybe?
""" Firefox and Chrome disable pin validation for pinned hosts whose validated certificate chain terminates at a user-defined trust anchor (rather than a built-in trust anchor). This means that for users who imported custom root certificates all pinning violations are ignored.
"""
https://developer.mozilla.org/en-US/docs/Web/HTTP/Public_Key...