Skip to content

Journal

The query file Search is not allowed to keep

Privacy-first is a product rule about advertising files, not a claim that Search never sees the words you typed.

Updated 26 August 2026 · Oernoe Editorial Team

The earlier document on this URL was a general essay about privacy-first search. It restated a thesis that already lived on About, on two other journal posts, and on the ads guide. That is how a site ends up with length and still looks thin. This replacement is narrower: what happens to a query on search.oernoe.com after you hit enter, and what is not allowed to happen next.

Oernoe Search has to see the query. A search engine that cannot read the words cannot return links. The promise we will stand behind is not “we are blind.” It is: we do not turn that query history into an advertising profile, and we do not sell account or search data to advertisers for their own marketing.

What has to exist for Search to work

When you type a query, the browser sends a request to search.oernoe.com. The service needs the query string, the fact that a client asked, and enough technical context to return a page and to notice abuse. IP address, user agent, and timestamps show up in ordinary request logs the same way they show up on almost every site that is not lying. Those logs are for uptime and security. They are not a product we sell.

If you are signed in, the account can attach preferences and history that you can see in the product. That is still not an advertising file. It is the difference between “remember what I searched yesterday so I can go back” and “remember what I searched yesterday so a network can bid on me.” The first can exist. The second is the thing this product is not allowed to build.

Signed-out search still has to function. We do not require an account to type a query. That also means we do not get to hide behind “only signed-in users have logs.” Signed-out requests still hit the server. The rule about advertising profiles has to hold either way.

If you use Search as your default engine, the browser will send every address-bar query here. That is more convenient and more revealing to our servers, not to an ad graph we sell. Default-engine instructions belong in How-To. This page is only about what we are allowed to do with the string after it arrives.

What is not allowed to happen next

The query is not allowed to become a segment we sell. It is not allowed to become a remarketing list. It is not allowed to be joined, by us, to a Google ad request on www.oernoe.com so that an article about privacy can be targeted with the search you ran an hour ago. If a ranking idea needs that join, the ranking idea does not ship.

This is a product rule Angel Mejia Rodriguez uses when a feature is proposed: does it give people more control over their data, or less? A query file for advertisers is less. It does not ship. That sounds simple until someone suggests a “harmless” improvement that only works if you already know the person. Then the rule has to do actual work.

We also do not treat crawl as a harvesting job for email lists. The crawler fetches public pages so the index can exist. It should not fetch Health notes, Chat threads, Drive files, or account settings. Those surfaces are not the public web. The crawl write-up is What Oernoe Search crawls, and what it does not.

The split people get wrong

www.oernoe.com is a publisher site. Selected finished pages may load Google AdSense. Google may then process page context, cookies, IP address, and device data to serve and measure those ads. That is described in the Privacy Policy. It is not Search selling your queries. Mixing those two systems into one sentence about “Oernoe tracking” is how older homepage copy ended up promising zero tracking while this company was applying for AdSense.

The ads guide is Search queries and Google ads. The hostname map is Which Oernoe hostname does what. If you only remember one check: view-source on a How-To page can include the AdSense client; view-source on search.oernoe.com should not.

What we will still admit

Security logs can retain request data longer than a session. Abuse has to be reconstructable or the service becomes a spam cannon. We will not publish a fake retention number to sound stricter than the Privacy Policy. If Privacy and this article disagree, Privacy wins and this article gets a correction.

We also cannot erase a Google ad request that happened on www because you later deleted an Oernoe account. Those are different controllers. Account deletion is described in How a privacy request is handled. Ad choices live at Google Ads Settings. Pretending otherwise is the same class of error as “zero tracking.”

Listings people submit to Search are public because someone asked them to be. Approval is slow on purpose. A listing is not a query file. It is a document in the index. If a listing about you should come down, that is a takedown of an index object, not a privacy export of your searches.

How to test the claim

Use Search signed out. Use Search signed in. Confirm both return links. Open Account and look for a setting that would share query history with advertisers. There is not one, because that product does not exist. Open this publisher site on How-To and confirm ads can load there. Open About and confirm they do not. If those checks fail after a deploy, this article is wrong the same day.

“Privacy-first” on this site now has a concrete meaning: no query file for ads, no sale of account or search data, ads isolated to finished publisher pages, and a public correction when we over-claim. Anything puffier than that does not belong on this URL.