Honest limits

A browser is not a VPN and does not hide your IP address. Search suggestions, if you opt in, go to the engine you chose; that engine still sees those requests. Tracking protection is list-based and not absolute: known ads, analytics, and social trackers from bundled lists are blocked on the device, but no blocker catches everything. Private Browser Incognito is rated 17+ for unrestricted web access and is intended for adults.

A search box that completes your thought is sending your thought, in pieces, to someone else. Each keystroke can be a request. The unfinished query is often more revealing than the one you meant to submit. A private browser that forgets locally and still streams prefixes to an engine has a hole in the first second of use. Suggestions should be off until you ask.

Private Browser Incognito keeps them off by default. You can search with Google, Bing, DuckDuckGo, Wikipedia, or a custom engine. The app asks before sharing a keystroke. A query you submit on purpose still goes to that engine. This article is about the extra traffic, why the default is closed, and what an engine still sees when you do search. It is not a claim that search is anonymous.

What a suggestion request actually contains

Autocomplete is not a local dictionary. For a web search engine it is usually a live lookup: the characters in the field, plus whatever the engine’s endpoint already knows how to attach. That can be enough to infer a medical concern, a legal question, a gift, or a name before you have decided to look it up. You might delete the query. The prefix may already have left.

Those requests are ordinary web traffic to the engine you selected. They use the network. The engine sees an IP address. HTTPS can encrypt the contents in transit, which is why HTTPS-Only Mode is on by default in this app, and why the app asks before falling back to HTTP. Encryption does not hide the fact of the lookup from the engine. For that default, see HTTPS-Only Mode: Why a Private Browser Starts Encrypted.

Suggestions are also easy to confuse with on-device blocking. Blocking stops known ads, analytics, and social trackers from bundled Disconnect lists. It does not stop a search you (or the suggestion endpoint) send to an engine you chose. Those are different destinations. The lists ship in the app. Suggestion traffic, when enabled, is opt-in by design. Mixing the two in one sentence is how products overclaim.

There is no local history file of the prefixes either way. Every tab is a private session in memory. The privacy question for suggestions is not “will this appear under Recents?” It is “did a server you do not control receive a partial query you did not mean to send?” Off until you ask is the answer that keeps that server out of the first tap.

Off by default, then an explicit ask

Defaults decide most sessions. A switch buried under Search that starts on will stay on. Private Browser Incognito starts suggestions off. The first time the feature would need to share a keystroke, the app asks. That matches HTTP fallback and other exits from the device: camera permission for Intruder Photo is asked when you enable the feature, never at the lock screen. A keystroke is not as dramatic as a photo. It is still someone else’s log.

If you agree, suggestions talk to the engine currently selected. If you refuse, you still have a search field. You type a complete query and submit it. The engine then sees one request instead of a trail of prefixes. That is the whole bargain. We do not silently retry. We do not send the prefixes to ourselves. There is no app server for browsing. The App Store privacy label is Data Not Collected.

Turning suggestions on later is still your choice. Turning them off again should be possible in the same settings neighborhood as the engine picker. We will not invent a dark pattern that keeps the endpoint warm. The network the app makes, as documented in the facts we ship against, is page loads, opt-in suggestions, downloads you start, and StoreKit. Suggestions belong on that list only after the ask.

This is not a lecture against convenience. Completing a query is useful on a bouncing train. It is also a feed. A private browser should treat it as a feed. The product that never mentions the feed is the one that trained you not to notice it.

Private Browser IncognitoSearch suggestions off until you ask. Engines you choose. Get the app

Google, Bing, DuckDuckGo, Wikipedia, or custom

The engine is yours. Presets cover Google, Bing, DuckDuckGo, and Wikipedia. A custom engine is for the destination you actually want: a specialized index, a local instance, whatever URL template you configure. We do not proxy the query. We do not rewrite it to a partner. We do not rank engines as morally ordered. Each one has a privacy policy you can read on that engine’s site. This article will not pretend to summarize them.

What we can say is architectural. Private Browser Incognito has no accounts and no sign-in. Search does not require an app login. If you are signed into the engine itself in that tab, that is the engine’s session, not ours. Cookies for that session live until you erase. One-tap erase closes every tab and destroys cookies, cache, and site data. The engine may still have its own log. We cannot erase another company’s servers.

A custom engine is the sharpest version of that honesty. You chose the destination. The suggestions endpoint, if you opt in, will be whatever that engine exposes. We do not audit it. We do not sit in the middle. If you point the field at a host you do not trust, the field will trust it. That is the cost of “bring your own.” The matching idea for accounts in general is Why a Private Browser Should Not Need an Account.

Wikipedia as a search destination is still a site visit. DuckDuckGo is still a site visit. Google and Bing are still site visits. Switching engines changes who receives the query. It does not hide your IP from that recipient. It does not replace on-device blocking for the results page that comes back. Ads, analytics, and social trackers on a results page are still list-based and not absolute. See On-Device Ad and Tracker Blocking on iPhone.

Search versus the rest of the session

People fold search into “private browsing” as if the omnibox were the whole product. It is one door. The other doors are a session with no history file, lists that ship on the device, HTTPS-Only Mode, erase, and App Lock. You can search privately on disk and loudly on the network. You can also skip search entirely and type a URL. Suggestions only apply to the as-you-type path.

Action What leaves the phone Default in this app
Typing with suggestions off Nothing until you submit This is the shipping default
Typing with suggestions on Prefixes to the chosen engine Only after you agree
Submitting a search The query, to that engine Always a site visit you chose
Opening a result A page load to that host Lists may block extra trackers

Erase after a search destroys the local session. It does not unsend the query. If the threat is a person holding the phone, erase and App Lock matter more than suggestions. If the threat is an engine building a prefix log, the default off switch is the control. If the threat is a network that should not see destinations, you are shopping for a VPN, which this app is not.

What we do not claim about search

We do not claim private search as a protocol. We do not claim the engine forgets. We do not claim Wikipedia is “safer” in a numbered way. We do not claim DuckDuckGo as our product. We do not bundle an analytics SDK that watches the box. There are no ads in the app. There are no third-party SDKs. Your traffic goes to the sites you visit, to a search engine if you search, and to Apple if you buy Stealth Suite.

Rated 17+ still applies. Unrestricted web access includes whatever you type into a search field. You are responsible for what you visit and for using the app lawfully. Suggestions being off does not make a query appropriate. It only keeps the unfinished version off the wire until you decide. That is a small, load-bearing default. It belongs next to HTTPS-Only Mode and next to lists that never download themselves at runtime. A private browser starts by not speaking until you mean it.

Private Browser IncognitoFree on the App Store. No history, on-device blocking, one-tap erase. Get the app

Frequently asked questions

Are search suggestions on by default in a private browser?

In Private Browser Incognito they are off by default. The app asks before sharing a keystroke with the search engine you chose. You can still search. A query you submit on purpose still goes to that engine. Suggestions are the extra requests that fire while you type.

Which search engines can I use in Private Browser Incognito?

Google, Bing, DuckDuckGo, Wikipedia, or a custom engine. The destination is yours. We do not proxy the query and we do not run an app server for browsing. Suggestions, if you opt in, go to that same engine as you type.

Do search suggestions hide my IP address?

No. A suggestion request is ordinary HTTPS traffic to the engine. That engine sees the partial query and your IP address. Turning suggestions off means those partial queries are not sent. It does not hide your IP when you later submit a search or open a page. A browser is not a VPN.

If suggestions are off, can the search engine still see my query?

Yes, once you submit it. Off by default only stops the as-you-type requests. The completed search is still a page load to Google, Bing, DuckDuckGo, Wikipedia, or your custom engine. The private browser does not keep a local history file of that search. The engine can still log it on its side.

Do I need an account to search in a private browser?

You should not. Private Browser Incognito has no accounts, no sign-in, and no app server for browsing. Search does not require an app login. If you are signed into the search engine itself in that tab, that is the engine’s account, not ours. Suggestions stay off until you agree to share a keystroke.