DystO

🥷 Privacy-first meta-search engine

Privacy

What is not collected

No accounts, no analytics, no fingerprinting, no cookies other than the single preferences cookie you control. Queries are not written to disk. Application error logging is disabled in code, not merely by configuration.

What the server unavoidably sees

To answer a request at all, the server processes your address and request headers in memory. Rate limiting hashes that address with a per-instance secret and truncates it to a /24 (or /64) before it is ever used as a key, and the entry expires within two minutes.

Caching

Result caching is optional and stores entries under keys derived by HMAC, so nothing readable — no query, no URL — reaches the filesystem. Set cache.ttl to 0 to disable it entirely.

Third parties

Your browser talks to this instance and to nothing else while you browse results: no CDN, no font service, no remote stylesheet, no remote image. Following a result link is, of course, a normal visit to that site — DystO sends no referrer.

The operator

A meta-search instance is only as private as whoever runs it. That is the point of the licence: read the code, and if you would rather trust yourself, host your own.