SearXNG vs Startpage vs DuckDuckGo vs Qwant
What each private search engine does with your query: index source, where it runs, what its privacy page says, and what breaks when you run SearXNG yourself.
SearXNG vs Startpage vs DuckDuckGo vs Qwant: the short answer
SearXNG vs Startpage vs DuckDuckGo vs Qwant comes down to one question: who sees your search query, and from which IP address. The three hosted engines answer it the same way. Your query joins millions of others behind their servers, and the company running the engine is the one you have to trust. SearXNG answers it differently. There is no company. Your own server sends the query to Google and Bing, and the IP address they see is the address of your VPS (virtual private server).
That is the whole trade. A hosted engine hides you in a crowd and asks you to believe its privacy page. A SearXNG instance removes the company, but it puts one IP address, yours, in front of engines that treat a single busy address as a bot. If you run agents or Open WebUI, SearXNG wins. It also wins for a team that wants one shared search box with an API (application programming interface). If you are one person searching from a phone, a hosted engine wins. The rest of this comparison explains both halves.
What each engine does with your query
The four engines differ in two things a privacy page rarely makes obvious: where the results come from, and which IP address the upstream index sees. Everything below was read from each engine's own pages on 12 September 2026, with the page date noted where one is printed. Where a page does not say something, the rows below leave it out.
DuckDuckGo
DuckDuckGo is a hosted engine run by a US company. Its results help page says that traditional links and images are results "which we largely source from Bing", and that the company has "maintained our own crawler (DuckDuckBot) and many indexes to support our results". So the index is mostly Microsoft's, with DuckDuckGo's own crawler and its instant-answer sources layered on top. When you search, DuckDuckGo's servers query Bing. Bing sees DuckDuckGo's addresses, not yours.
Its privacy page (marked "Last updated 06-03-26" at the bottom) says: "We don't save your IP address alongside your searches, Duck.ai chats, or visits to our websites, and we never log IP addresses to disk that could be tied back to you." It also says "We have no way to create a history of your search queries, your chats, or the sites you browse." The money comes from ads: "Search ads on DuckDuckGo are based on the search results page you're viewing, and not based on you as a person." Ad clicks go through Microsoft: "Ad clicks are managed by Microsoft's ad network and Microsoft has committed to not associate your ad-click behavior with a user profile and to not store or share that information other than for accounting purposes." That last line is a promise by Microsoft that DuckDuckGo relays, so the trust chain has two links.
Startpage
Startpage is a hosted engine operated by Surfboard Holding BV in The Hague, in the Netherlands. It has no index of its own. Its support page says "Startpage submits your query to Google and Bing anonymously on your behalf, then returns the results to you, privately." Google was the only source for years. A Startpage blog post dated 28 February 2023 added "Bing is now one of our search partners." Google and Bing see Startpage's addresses, not yours. Ads are contextual, matched to the keyword you typed rather than to a profile, according to the company. The Anonymous View feature opens a result page through a Startpage proxy, so the site you visit sees Startpage's address as well.
The ownership question is the one readers ask most, so here is the dated fact. In October 2019, Privacy One Group, a subsidiary of the US advertising company System1, bought a majority stake in Surfboard Holding BV. Startpage says its founders keep a stake and can reject any technical change that would harm user privacy. Whether that reassures you is your call. The fact that an advertising company holds the majority is not in dispute.
One honesty note. Startpage's policy could not be fetched by machine on 12 September 2026, because startpage.com refuses automated clients. The statements above are Startpage's own words as quoted by its Wikipedia entry and by the Privacy Guides forum, including the company's statement that it stopped recording user IP addresses in January 2009. Open startpage.com/en/privacy-policy in a browser and read it yourself before you rely on any of this.
Qwant
Qwant is a hosted engine run from Paris. Its privacy page (updated 20 August 2026, printed as "Mise à jour : 20/08/2026") names the data controller as "Qwant, located at 42 avenue de la Porte de Clichy 75017, Paris". Since 2023 the company has been owned by Synfonium, a holding of OVHcloud founder Octave Klaba, with the French public bank Caisse des Dépôts as minority shareholder.
Of the three hosted engines, Qwant is the one building a general web index of its own, and as of September 2026 that index is still partial. In November 2024 Qwant and Ecosia formed a joint venture, European Search Perspective, to build a European index called Staan. It began serving part of Qwant's results in August 2025, and a German index has since followed. The rest still comes from Microsoft. The privacy page says so plainly: "we have a partnership with Microsoft for the provision of our search results and the provision of contextual advertisements".
What Qwant sends to Microsoft is listed on the page, and it is more detail than the other two hosted engines admit to sending anywhere. The list includes "The search keywords", "The first three bytes of your IP address", "The approximate geographic area from which the search originates, at the scale of a region or a city", and "The salted hash generated from your IP address, your User Agent and a salt changing at the latest every 3 months". The page says "This data is transmitted to this partner within the European Union". For its own statistics, Qwant keeps a "salted hash of the IP address (with a salt changing at the latest every three months)" and says "The data is aggregated and retained by Qwant for 25 months". Read that as what it is: pseudonymised, which is a weaker word than anonymous. A truncated address plus a keyword is not a name, but it is not nothing.
SearXNG
SearXNG is not a hosted engine. It is free software that you run. It is the fork of searx that replaced the original, and it is the one still maintained. It has no index. Its documentation describes "a free internet metasearch engine which aggregates results from up to 267 search services" (the count as of September 2026) and states "Users are neither tracked nor profiled." When you search, your instance sends the query to whichever engines you enabled, Google and Bing among them, with identifying data removed from each request, and merges what comes back.
There is no logging policy to cite, because there is no publisher. The project's own page on running a private instance puts it this way: "everything is in their control: the source code, logging settings and private data." That is true in both directions. Nothing is logged unless you log it, and nginx writes client IPs to its access log by default, so how safe SearXNG really is depends on the person who set it up, which is you.
The sentence in the docs that matters most is short: "The IP address used will be the IP of the instance." Google sees your VPS. Bing sees your VPS. If an instance is abused, the docs warn, the result is "external service to enforce CAPTCHAs or to ban the IP address". Nothing about that changes when the instance is private. You simply have fewer users producing the load.
The comparison, row by row
Index source
- DuckDuckGo: mostly Bing, plus its own crawler and instant-answer sources.
- Startpage: Google and Bing. Nothing of its own.
- Qwant: its own Staan index for part of the results, Bing for the rest.
- SearXNG: none. It queries the engines you enable and merges the answers.
Where it runs
- DuckDuckGo: servers operated by a US company. The privacy page does not name a hosting region.
- Startpage: a Dutch company in The Hague, majority owned by a US advertising company since October 2019.
- Qwant: a French company in Paris. Its page says the data it shares with Microsoft stays within the European Union. It does not name a hosting provider.
- SearXNG: your VPS, in whatever country you rented it.
Logging, as published on 12 September 2026
- DuckDuckGo: "we never log IP addresses to disk that could be tied back to you".
- Startpage: the company states it stopped recording user IP addresses in January 2009. Second-hand, see the note above.
- Qwant: a salted hash of the IP, aggregated and kept for 25 months, plus a truncated IP with keywords sent to Microsoft.
- SearXNG: whatever you configure. No policy exists until you write one.
Cost
- DuckDuckGo: free. Funded by keyword ads served through Microsoft and by a paid subscription.
- Startpage: free. Funded by keyword ads.
- Qwant: free. Funded by contextual ads supplied by Microsoft.
- SearXNG: the software is free. You pay for a VPS and for your own time.
What breaks
- DuckDuckGo: results depend on Bing. When Bing is down, the links are too.
- Startpage: results depend on a paid deal with Google. Trust depends on how you read the System1 ownership.
- Qwant: the Wikipedia entry records that during a Bing API outage in 2024, Qwant stopped showing results.
- SearXNG: rate limits and CAPTCHAs against your one IP address, plus the upkeep of a server.
The honest trade: a crowd, or your own IP
A hosted engine puts millions of queries behind a handful of addresses. Google and Bing already know those addresses belong to DuckDuckGo or Startpage, and the volume is expected, and in Startpage's case paid for. Your query is one of millions. The engine could log you. The upstream index cannot single you out.
A SearXNG instance inverts this. Your VPS is one address with no contract behind it, and it sends requests that look like a browser but arrive at a rate no human types. The upstream engine reads that pattern as automation. What happens next is an HTTP 429 (too many requests) or a CAPTCHA (a challenge page a human must solve) in place of results. Some engines send a 403 (forbidden) instead. SearXNG sees the error and suspends that engine for a fixed time, so the instance stops making things worse. The default suspension times in settings.yml, stored there in seconds, show how seriously the project takes each kind of failure.
The data behind this chart
[
{
"label": "Too many requests (HTTP 429)",
"hours": 1
},
{
"label": "Access denied (HTTP 402 or 403)",
"hours": 24
},
{
"label": "CAPTCHA, generic",
"hours": 24
},
{
"label": "Google reCAPTCHA",
"hours": 168
},
{
"label": "Cloudflare CAPTCHA",
"hours": 360
}
]A 429 costs you 1 hour of that engine. A generic CAPTCHA costs 24 hours. A Google reCAPTCHA costs 168 hours, which is a week, and a Cloudflare challenge costs 360 hours, which is fifteen days. During that time the HTML page lists the engine in its error box with the text "CAPTCHA" or "too many requests" (or "access denied" for a 403), and the JSON API lists it under unresponsive_engines. Results still arrive from the engines that are not suspended, which is why an instance with only Google enabled feels broken and an instance with six engines feels fine.
If this is where you are right now, two sibling posts hold the fixes: why SearXNG returns 429 errors and what the limiter and outgoing settings change, and what to do when Google answers your instance with a CAPTCHA. The short version: fewer requests per engine, more engines, sane timeouts, and a limiter in front of any instance other people can reach.
The trade in one line. A hosted engine asks you to trust a company with your query and gives you a shared address in return. SearXNG asks you to trust nobody and gives you a single address that stands alone in return.
When self-hosting SearXNG wins
You need a JSON API. The three hosted engines deliver results to humans in a browser. None of them publishes a web results API for individuals. SearXNG has a JSON endpoint, and it is off by default. Enable it in settings.yml:
search:
formats:
- html
- jsonThen check it from any machine:
curl -s -o /dev/null -w '%{http_code}\n' 'https://search.example.com/search?q=wireguard+mtu&format=json'200 means JSON is on. 403 means json is missing from search.formats, because the request handler calls flask.abort(403) for any format not in that list. With it enabled, one call returns the merged results:
curl -s 'https://search.example.com/search?q=wireguard+mtu&format=json' | jq '.results[:3][] | {title, url, engine}'Each result carries title, url, content and the engine it came from. The response also holds answers, suggestions, infoboxes and unresponsive_engines. That endpoint is what Open WebUI's web search and coding agents with a browser-search skill call. An agent that searches fifty times an hour is exactly the client a hosted engine blocks, and exactly the client a private instance exists for.
You want no ads and no partner. Every hosted engine on this page pays its bills with ads, and two of the three route those ads through Microsoft. SearXNG serves no ads and has no ad partner. The docs state it as a design goal: "SearXNG does not serve ads or tracking content, unlike most search services."
You want to mix engines. A hosted engine gives you one index, or two. SearXNG lets you query Google, Bing, Brave, Wikipedia and a documentation site in one request and rank the union. For technical searches this is the feature people stay for. The same query against several indexes surfaces the page that only one of them ranks well.
You are a team. One instance shared by ten people is closer to a hosted engine than a personal one is. Ten people's queries hide each other a little, and one person owns the config for all of them. That instance needs a limiter and a reverse proxy done properly, which is the hardening a shared SearXNG instance needs before anyone outside your house can reach it.
When a hosted engine wins
One person, one phone. Your instance is one address that searches for exactly one human, so the crowd you hide in has one person in it. Google cannot put a name on that address, but a stream of queries from an address that never changes is a profile whether or not a name is attached. A hosted engine's shared address does more for a single user than a private VPS does.
The second reason is upkeep. A phone on a mobile network reaches a hosted engine in the time it takes to load the page. It reaches your VPS through whatever you put in front of it: a domain, a TLS (transport layer security) certificate, a reverse proxy, and a limiter that must not block your own phone. When Google suspends your instance for a week, you are the one who notices, and you are the one who fixes it. For a single person, that is real work for a benefit the crowd already gives you.
The third reason is the phone itself. A hosted engine ships an app and a browser integration that set it as the default search. Your instance can be set as a custom search engine in Firefox and in most Android browsers, and it works, but every new device is a manual step. If that sounds like a chore, it is, and it is a fair reason to pick DuckDuckGo or Startpage and move on.
How to read a privacy page without being fooled
The four pages above use different words for similar things, and the differences matter. Four checks catch most of it.
- Find the printed date. A page with no date can change under you with no record. DuckDuckGo and Qwant print one. Copy the date into your own notes when you decide to trust a page.
- Search the page for the word "partner". A partner is a second company that sees something. DuckDuckGo names Microsoft for ads. Qwant names Microsoft for results and ads. What the partner receives is the sentence to read twice.
- Look for a retention period. "We don't log" is a claim with no number. "Retained for 25 months" is a claim you can check against. Qwant is the only one of the three that prints a number, and that transparency counts for Qwant even though the number is long.
- Read "alongside" carefully. "We don't save your IP address alongside your searches" is a precise sentence. It says the two are not stored together. It does not say the address is never seen, and it does not say the query is never stored. That is the sentence DuckDuckGo chose, and it is honest, so read it as written.
None of this makes any of the four engines a bad choice. It makes the choice yours, on facts you checked on a date you wrote down, which is the only kind of privacy decision that lasts.
Where to go next
If SearXNG is the right answer for you, the install is a Docker Compose file and a settings.yml behind a reverse proxy, and the SearXNG self-hosting guide walks through all of it, including the limiter that keeps your address off the block lists. If what you wanted all along was a search engine over your own material rather than a private front for Google, Hister, a personal search engine you host yourself is a different tool for a different problem, and its own guide covers it.
FAQ
Is SearXNG more private than DuckDuckGo?
It removes a different risk. DuckDuckGo asks you to trust one company's privacy page, and that page says it never logs IP addresses to disk in a way that could be tied to you. SearXNG asks you to trust nobody, because the software runs on your server, but the engines it queries see your VPS address on every request. For one person, DuckDuckGo's shared address hides you better. For an agent or a team that needs a JSON API, SearXNG is the one that works at all.
Does Startpage still use Google results?
Yes. Startpage's support page says it submits your query to Google and Bing anonymously on your behalf, and a Startpage blog post from 28 February 2023 announced Bing as a second search partner. Startpage has no index of its own. Its results are proxied Google and Bing results served by a Dutch company that has been majority owned by the US advertising company System1 since October 2019.
Why does my SearXNG instance keep getting CAPTCHAs from Google?
Because every query leaves from one IP address, your VPS, at a rate that looks automated. Google answers with a CAPTCHA page instead of results, and SearXNG then suspends its Google engine for the time set in settings.yml, which is 168 hours (a week) for a reCAPTCHA by default. Enable more engines so results keep flowing, and lower the request rate per engine. Put the limiter in front of any instance other people can reach before you change anything else.
Which of these search engines has its own index?
Two of them, partly. DuckDuckGo runs its own crawler, DuckDuckBot, but says its links and images are largely sourced from Bing. Qwant serves part of its results from Staan, the European index it is building with Ecosia, and the rest from Bing. Startpage has no index and proxies Google and Bing. SearXNG has no index by design and queries whichever engines you enable.
Can I call DuckDuckGo or Startpage from a script or an AI agent?
Not for web results. Neither publishes a web results API for individuals, and scraping the HTML page gets your address blocked the same way it gets a SearXNG instance blocked. SearXNG exposes a JSON endpoint at /search?q=...&format=json once json is listed under search.formats, and that endpoint is what Open WebUI and agent search tools expect.