You seem to know more about this than I do, but my layperson's takeaway from the Snowden revelations is that the NSA records every url we browse. Are you saying that's incorrect?
If that's the case, nowhere on the regular Internet is safe.
Snowden revealed that NSA has infiltrated all the major industry players (Apple, Microsoft, Google, etc.), also ISPs. But the only way NSA can know what your plaintext HTTPS URL is either by having access to your PC, or having access to Kagi's servers. Or as I said, that they've cracked encryption schemes everyone assumes to be safe.
Or if they have access to, or can subpoena, a MitMaaS for HTTPS. Like Cloudflare.