You're deep in a build. You ask your coding agent to "look up how X handles Y," or "find the latest on Z." It thinks for a second, comes back with an answer, you keep moving. It feels like the agent just knew — like the whole thing happened on your machine.

It didn't.

Where the query actually goes

When your agent searches the web, it isn't opening a browser on your laptop. It's calling a tool, and that tool runs on the provider's servers, not yours. The path looks like this:

Your machine
Your prompt
the sentence you typed
Your agent
running on your laptop
Leaves your machineunencrypted intent
Out of your hands · keeps a copy
Model provider
Anthropic · OpenAI
Upstream engine
Bing · Brave · Google

So two parties you never invited now hold a copy of your query — timestamped, and tied to your account or API key: the model provider, and whatever search engine they buy results from.

The part that matters

It's not the pages you looked at that leak. It's the query itself — the raw sentence describing what you were trying to figure out. That's usually the more revealing artifact. The page is public. The question is you at 2am, not yet knowing the answer, describing in your own words the exact thing you're building.

Why this is worse than normal browsing

I know — "everything you Google gets logged too." True. But agent search is a different shape of problem:

  • It's constant. An agent doesn't search once. It fans out — five, ten, twenty queries to answer a single task. All logged.
  • It's verbatim intent. A human types keywords. An agent often searches your actual phrasing: "how to work around the rate limit on <specific vendor> API for <specific use case>." That's not a keyword. That's a confession.
  • It's tied to identity. It goes out under your API key or your account. No incognito, no separation.
  • It's perfectly timed. The queries land in the exact order you're building things. Read the query stream and you can reconstruct the roadmap — what you're researching this week, what you'll ship next month, where you're stuck.

For a solo dev, that's your edge sitting in someone else's logs. For a company, it's your unreleased strategy narrated in real time to two vendors — and, potentially, to anyone who ever subpoenas or breaches them.

Being honest about the fix

I want to be precise here, because this is easy to oversell.

There's a self-hosted way to route agent search through your own infrastructure, so the raw query never leaves your control. (That's the next post — the actual how-to.) But the tools differ in how far you can take it:

  • Claude Code and Codex CLI let you turn the built-in search off and hand the agent your own search tool instead. This is the clean case. Your query goes to a search engine you run, which then fans out to public engines with your account nowhere in the chain. The model provider never sees it.
  • OpenAI's hosted web_search tool (the Responses API one) is different. You can't swap the engine underneath it — it always runs through OpenAI's backend. The only real move there is to not use that tool at all: give your agent your own function that calls your own search. Same destination, different door.

So the accurate framing isn't "reconfigure the provider's search to be private." It's: replace the provider's search tool with one you own. Where the tools let you do that — and the CLI coding agents do — you get real separation. Where they don't, you route around the built-in entirely.

And "one you own" is a spectrum, not a single choice. You don't have to self-host to make progress — you can point the agent at a hosted search API and already cut the model provider out of the loop. You're just trading two watchers for one you picked. Self-hosting is the far end, where the count goes to zero:

ToolSelf-host?Who sees your queryTied to youCost
Built-in search (default)NoModel provider + engineProvider accountMetered
Brave Search APINoBraveAPI keyFree tier + paid
TavilyNoTavilyAPI keyFree tier + paid
ExaNoExaAPI keyPaid
SearXNG (self-hosted)YesOnly public enginesNothingFree
Each step down removes a party that can tie a raw query to you — two for the default, one for a hosted API you chose, none for self-hosting.

The hosted APIs are a genuine improvement over the default, and if standing up a container isn't worth it to you, they're a reasonable stop. But notice what you're still doing: handing every raw query to one more company, tied to a key that's yours. SearXNG is the only row where nobody you didn't invite ends up holding the sentence.

What you actually run

The self-hosted piece is a metasearch engine. SearXNG is the one I use. It takes your query, fans it out to dozens of public engines, aggregates the results, and hands them back. Crucially, those public engines see a query arriving from your SearXNG box — not tied to your account, not tied to your agent session, not routed through a model vendor.

You bridge it to the agent over MCP (the tool protocol both Claude Code and Codex speak), flip the built-in search off, and that's it. SearXNG isn't the only option — there are others in the same spirit (Whoogle, self-hosted bridges in front of Brave or Tavily) — but SearXNG is the canonical, boring, works-everywhere choice.

What this actually buys you

Privacy of the query stream is the headline, but it isn't the only thing:

  • Your roadmap stays yours. The big one. What you research is what you're building. Keep it off other people's servers.
  • No rate walls, no per-query meter. The built-in searches are metered and throttled. Your own engine isn't. Secondary — but you'll feel it on a heavy research day.
  • Control and reproducibility. You choose which engines to trust. Search stops being a black box you can't inspect, and the only logs that exist are the ones you decide to keep.

None of this is anti-AI. I use agents all day — this is about how you wire them, not whether. The default is convenient, and it's genuinely fine for looking up public docs. But the moment your searches start describing something you haven't shipped yet, the default is quietly working against you. Ten minutes of setup takes it back.

Next: how to actually do it

In the follow-up I'll walk through the real setup — SearXNG in Docker, the MCP bridge, and the exact config to disable the built-in search in both Claude Code and Codex. And, like every tutorial here, it comes in two halves: do-it-yourself steps, and a copy-paste prompt you can hand straight to your coding agent to set the whole thing up for you.

Until then — next time your agent says "let me search for that," ask yourself who else is reading.