Yes without HTTP(S) all your details are sent over plain text. That’s what HTTP is. Securing this connection with a certificate is the preferred method. The choice is yours though.
i think i’m going to go down this route as i’ve used zerotier before and will just specify the zerotier ha address in the phone app, after installing the addon on ha and the zerotier app on the phones (zt on phones always connected with automatic restart)