They aren't going to see behind the TLS curtain, but they would see (assuming no DNS encryption) a domain name lookup followed by various traffic patterns; either:
Bursts (page loads) with near silence in between, maybe just some non-human-triggered traffic from scripts that poll.
Bursts (page loads) with quite a bit more of a human-triggered cadence in between, if lazy loading during scrolling occurs.
But mouse-tracking analytics probably result in a similar leak, if not better.