If that's the case, nowhere on the regular Internet is safe.
Snowden revealed that NSA has infiltrated all the major industry players (Apple, Microsoft, Google, etc.), also ISPs. But the only way NSA can know what your plaintext HTTPS URL is either by having access to your PC, or having access to Kagi's servers. Or as I said, that they've cracked encryption schemes everyone assumes to be safe.
Or if they have access to, or can subpoena, a MitMaaS for HTTPS. Like Cloudflare.
Couldn't you also just open an incognito window?
I'm just explaining the reason why some does it and saying it doesn't help against intermediaries who can eavesdrop.
Im fact I think I was tempted to write my exact thoughts about it yesterday but dropped it.
The reason some privacy oriented sites hide it is because of local snooping on your end point, i.e. if someone has access to your device when you are not there and can look through your logs and by extension search logs.