Crawlers find the web by walking links that are already public. How Oernoe Search works says that plainly: crawlers visit pages they already know about, follow public links, and return when a page changes. Search-and-ads says the resulting index is the public web plus listings people chose to submit through an approval step you can see in the product. That index is not a skeleton key for Health notes, Chat threads, Drive files, or account settings.
This essay is about that boundary. It is not the listings-approval essay. It is not the Docs-and-Drive-are-workspaces essay. It is not the Chat-and-Health-stay-off-publisher-ads essay. It is not a second pass on why approval is slow on purpose. Those arguments have their own homes. Here the claim is simpler: following public links is how Search grows an index, and private stores are not on that path.
## Public links are the discovery graph
A search index that cannot discover new URLs dies. Discovery, in the guide’s language, is not a side channel into locked accounts. It is the ordinary graph of the public web. A page that is fetchable without credentials can point to another page that is also fetchable. The crawler follows that edge. If the new page allows it under robots rules, the crawler may fetch it, analyze its public text, and add it to the index of documents Search can later rank.
That graph is incomplete by nature. Many pages are never linked. Many sites throttle or block crawlers. Many URLs require a session. Continuous crawl keeps known pages fresher; it does not invent a right to open a private file because the operator also runs a Drive product. Public links define the walk. Private stores define the stop.
Approved listings sit beside the public web as a second, smaller intake. Someone chooses to submit a people or company listing. An approval step runs. If it passes, the listing can appear in Search. That is still not Health. That is still not Chat. That is still not Drive. A listing is a public claim a person asked to put in the index. A Health note is a private workspace record. Mixing those sentences is how trust breaks.
## What the index is allowed to be
Search-and-ads draws the product promise in short lines. You type a query at search.oernoe.com. You get links. Oernoe does not use that query history to build an advertising profile, and it does not sell account or search data to advertisers for their own marketing. Search still sees ordinary request data needed to return a page: the query, the fact that a browser asked, technical logs for abuse and uptime. Those logs are not an advertising graph.
Then comes the index sentence that this essay leans on. Search also lets people add public people and company listings, with an approval step visible in the product. That is an index of the public web and of listings people chose to submit. It is not a way to open Health notes, Chat threads, Drive files, or account settings.
Read that last sentence again. It is not metaphor. It is a scope limit. If a reviewer or a user ever finds Search surfacing private Health text because someone happened to hold an Oernoe account, the published promise failed. Following public links cannot be stretched into following authenticated workspace objects.
## Private stores are different products
Health is a private workspace for notes and records someone chooses to keep. Chat is private conversation with account-level controls. Docs are collaborative documents with sharing the account holder can see. Drive is file storage for work and personal projects. Account settings are where profile, security, and preferences live. Tracker is status. None of those product shells are “public links” for the Search crawler to stroll through.
The homepage and About page present those services as separate hosts and separate jobs. Ads stay off the apps themselves. Search-and-ads lists Search, Health, Chat, AI, Docs, Drive, and Tracker as surfaces that do not load publisher ads. That advertising rule is related but not identical to the crawl rule. Ads-off protects private product UX from becoming inventory. Follow-public-links protects private product data from becoming Search corpus. Both rules exist because the same company runs both a publisher site and private apps.
Operator proximity tempts bad shorthand. Anoepal operates Search and www. Sharing an operator does not authorize a shared advertising file of queries. Sharing an operator also does not authorize treating Drive paths as crawl seeds. The honest architecture is boring: public documents enter through public fetch and public link edges; private objects stay behind account controls.
## Why people mash the systems together
Older homepage copy mashed privacy language across the whole network. Search-and-ads exists because that mash produced sentences like “zero tracking” next to an AdSense application. The fix was not louder privacy poetry. The fix was a map of two systems that must not share an advertising file of queries, and that also must not share a crawl path into private stores.
Users mash systems for a different reason. They see one account, one brand, and assume one database. Journal writing has to keep saying the boring truth. One free account can unlock several products. Those products still have different data classes. A query is not a Health note. A public listing is not a Chat thread. A ranked result is not an account settings export.
What we publish adds the editorial constraint. www is allowed to be original writing about search and privacy, help pages for products we actually run, and a legal and company record. It is not allowed to pretend unreleased shells are live products, and it is not allowed to treat private apps as publisher fodder. Following public links fits that discipline: Search’s corpus story stays tied to the public web and approved listings, not to a fantasy of total access.
## Crawling politeness still applies on the public path
Even on public pages, the crawler is not absolute. How Search works says Oernoe respects robots.txt files and crawl rate limits set by website owners. Privacy-first crawling refuses to store IP addresses, device information, or other identifying data during crawling as part of that process. Content analysis reads public page content, structure, and links for relevance, without harvesting contact addresses for advertising lists, tracking identities, or storing behavioral signals for ads.
Those restraints matter for this essay because “follow public links” can sound aggressive if you ignore them. Following a link is still subject to the destination’s robots rules. Rate limits still belong to site owners. Public does not mean unbounded. It means eligible for ordinary discovery when the publisher of that page allows it.
The destination’s robots file is not Oernoe’s private store policy. They answer different questions. Robots answers whether a public host wants to be crawled and how fast. Private-store policy answers whether authenticated Health or Drive objects are crawl targets at all. The answer to the second question is no, regardless of robots on www.
## Listings are opt-in public objects
Listings deserve a careful clause so this essay does not collide with the dedicated approval pieces. A listing enters because someone submitted it and an approval step ran. That is voluntary publicity, not a crawler kicking down a door. Once approved, a listing can sit in the same retrieval world as other public documents. Before approval, it is not a ranked public claim. After rejection, it should not linger as if it were.
That process is still not a bridge into private notes. Submitting a company listing does not grant Search the right to read the submitter’s Drive. Approving a people listing does not open Chat history. The intake channel is narrow on purpose. Keep it narrow in language too.
## How to verify without trusting marketing tone
Open How Oernoe Search works. Find the sentence about crawlers visiting known pages, following public links, and returning when pages change. Find the content analysis and privacy-first crawl restraints. Open Search queries and Google ads. Find the paragraph that defines the index as public web plus approved listings, and that names Health notes, Chat threads, Drive files, and account settings as out of scope. Open Privacy for the retention and advertising disclosures that apply to Search request data and to publisher ads on selected www pages.
Then open a private product host only as far as the public landing allows, and notice what you cannot see without signing in. That absence is the point. Search results are links and listings. They are not a file browser for someone else’s workspace.
If those checks diverge from this essay after a deploy, correct the essay or correct the product page the same day. The journal is supposed to be a checkable record, not a mood.
## What this essay refuses to imply
It does not imply that every public page will be found. Link graphs have holes. It does not imply that approval is instant. It does not imply that Docs and Drive are “basically public” because sharing exists; sharing is a control the account holder sets, not a crawl invitation to Search. It does not imply Chat or Health are ad inventory; Search-and-ads keeps ads off those apps. It does not claim the publisher site is free of ads; selected finished pages may show Google ads, disclosed in Privacy and Cookies.
It also does not invent scale theater. No fake user counts. No launch-hype swagger. Just the published path: public links in, private stores out.
## Discovery without credentials
A useful stress test asks what the crawler can obtain with no account cookie and no special operator privilege. If the answer is a normal public HTML response, the URL is a candidate for public-link discovery, subject to robots rules and rate limits. If the answer is nothing useful until someone signs in, the URL is a private store edge, not a crawl seed.
That test keeps engineering honest when product hosts share design language. A landing page that explains Health can be public; the note list behind sign-in cannot. A Chat product description can be public; the thread transcript cannot. Drive’s overview can be public; the file bytes cannot. Account help copy can be public; the settings row cannot. Following public links only ever applies to the first half of each pair. Ranking then scores that public half against a query. Equal results for equal queries stay coherent because the corpus was never a per-user private vault.
## Editorial discipline on the same theme
What we publish says the recovery from thin promotional stubs is a smaller, stricter public index of real documents. Journal essays about Search corpus rules belong there: they add a method and a boundary. The method here is link-following on the public web. The boundary is private product data. If an older sentence ever implied Search could see everything in an Oernoe account, that sentence should be corrected in public. Follow public links, not private stores, is the corrected shape.
## Closing the loop
Follow public links. Index public pages and approved listings. Rank those documents against queries without turning query history into an advertising profile. Leave Health notes, Chat threads, Drive files, and account settings where they belong: behind account controls, off the crawler’s path. That is the Search corpus story we will stand behind, and it is smaller than the brand’s total surface on purpose.
This essay is about that boundary. It is not the listings-approval essay. It is not the Docs-and-Drive-are-workspaces essay. It is not the Chat-and-Health-stay-off-publisher-ads essay. It is not a second pass on why approval is slow on purpose. Those arguments have their own homes. Here the claim is simpler: following public links is how Search grows an index, and private stores are not on that path.
## Public links are the discovery graph
A search index that cannot discover new URLs dies. Discovery, in the guide’s language, is not a side channel into locked accounts. It is the ordinary graph of the public web. A page that is fetchable without credentials can point to another page that is also fetchable. The crawler follows that edge. If the new page allows it under robots rules, the crawler may fetch it, analyze its public text, and add it to the index of documents Search can later rank.
That graph is incomplete by nature. Many pages are never linked. Many sites throttle or block crawlers. Many URLs require a session. Continuous crawl keeps known pages fresher; it does not invent a right to open a private file because the operator also runs a Drive product. Public links define the walk. Private stores define the stop.
Approved listings sit beside the public web as a second, smaller intake. Someone chooses to submit a people or company listing. An approval step runs. If it passes, the listing can appear in Search. That is still not Health. That is still not Chat. That is still not Drive. A listing is a public claim a person asked to put in the index. A Health note is a private workspace record. Mixing those sentences is how trust breaks.
## What the index is allowed to be
Search-and-ads draws the product promise in short lines. You type a query at search.oernoe.com. You get links. Oernoe does not use that query history to build an advertising profile, and it does not sell account or search data to advertisers for their own marketing. Search still sees ordinary request data needed to return a page: the query, the fact that a browser asked, technical logs for abuse and uptime. Those logs are not an advertising graph.
Then comes the index sentence that this essay leans on. Search also lets people add public people and company listings, with an approval step visible in the product. That is an index of the public web and of listings people chose to submit. It is not a way to open Health notes, Chat threads, Drive files, or account settings.
Read that last sentence again. It is not metaphor. It is a scope limit. If a reviewer or a user ever finds Search surfacing private Health text because someone happened to hold an Oernoe account, the published promise failed. Following public links cannot be stretched into following authenticated workspace objects.
## Private stores are different products
Health is a private workspace for notes and records someone chooses to keep. Chat is private conversation with account-level controls. Docs are collaborative documents with sharing the account holder can see. Drive is file storage for work and personal projects. Account settings are where profile, security, and preferences live. Tracker is status. None of those product shells are “public links” for the Search crawler to stroll through.
The homepage and About page present those services as separate hosts and separate jobs. Ads stay off the apps themselves. Search-and-ads lists Search, Health, Chat, AI, Docs, Drive, and Tracker as surfaces that do not load publisher ads. That advertising rule is related but not identical to the crawl rule. Ads-off protects private product UX from becoming inventory. Follow-public-links protects private product data from becoming Search corpus. Both rules exist because the same company runs both a publisher site and private apps.
Operator proximity tempts bad shorthand. Anoepal operates Search and www. Sharing an operator does not authorize a shared advertising file of queries. Sharing an operator also does not authorize treating Drive paths as crawl seeds. The honest architecture is boring: public documents enter through public fetch and public link edges; private objects stay behind account controls.
## Why people mash the systems together
Older homepage copy mashed privacy language across the whole network. Search-and-ads exists because that mash produced sentences like “zero tracking” next to an AdSense application. The fix was not louder privacy poetry. The fix was a map of two systems that must not share an advertising file of queries, and that also must not share a crawl path into private stores.
Users mash systems for a different reason. They see one account, one brand, and assume one database. Journal writing has to keep saying the boring truth. One free account can unlock several products. Those products still have different data classes. A query is not a Health note. A public listing is not a Chat thread. A ranked result is not an account settings export.
What we publish adds the editorial constraint. www is allowed to be original writing about search and privacy, help pages for products we actually run, and a legal and company record. It is not allowed to pretend unreleased shells are live products, and it is not allowed to treat private apps as publisher fodder. Following public links fits that discipline: Search’s corpus story stays tied to the public web and approved listings, not to a fantasy of total access.
## Crawling politeness still applies on the public path
Even on public pages, the crawler is not absolute. How Search works says Oernoe respects robots.txt files and crawl rate limits set by website owners. Privacy-first crawling refuses to store IP addresses, device information, or other identifying data during crawling as part of that process. Content analysis reads public page content, structure, and links for relevance, without harvesting contact addresses for advertising lists, tracking identities, or storing behavioral signals for ads.
Those restraints matter for this essay because “follow public links” can sound aggressive if you ignore them. Following a link is still subject to the destination’s robots rules. Rate limits still belong to site owners. Public does not mean unbounded. It means eligible for ordinary discovery when the publisher of that page allows it.
The destination’s robots file is not Oernoe’s private store policy. They answer different questions. Robots answers whether a public host wants to be crawled and how fast. Private-store policy answers whether authenticated Health or Drive objects are crawl targets at all. The answer to the second question is no, regardless of robots on www.
## Listings are opt-in public objects
Listings deserve a careful clause so this essay does not collide with the dedicated approval pieces. A listing enters because someone submitted it and an approval step ran. That is voluntary publicity, not a crawler kicking down a door. Once approved, a listing can sit in the same retrieval world as other public documents. Before approval, it is not a ranked public claim. After rejection, it should not linger as if it were.
That process is still not a bridge into private notes. Submitting a company listing does not grant Search the right to read the submitter’s Drive. Approving a people listing does not open Chat history. The intake channel is narrow on purpose. Keep it narrow in language too.
## How to verify without trusting marketing tone
Open How Oernoe Search works. Find the sentence about crawlers visiting known pages, following public links, and returning when pages change. Find the content analysis and privacy-first crawl restraints. Open Search queries and Google ads. Find the paragraph that defines the index as public web plus approved listings, and that names Health notes, Chat threads, Drive files, and account settings as out of scope. Open Privacy for the retention and advertising disclosures that apply to Search request data and to publisher ads on selected www pages.
Then open a private product host only as far as the public landing allows, and notice what you cannot see without signing in. That absence is the point. Search results are links and listings. They are not a file browser for someone else’s workspace.
If those checks diverge from this essay after a deploy, correct the essay or correct the product page the same day. The journal is supposed to be a checkable record, not a mood.
## What this essay refuses to imply
It does not imply that every public page will be found. Link graphs have holes. It does not imply that approval is instant. It does not imply that Docs and Drive are “basically public” because sharing exists; sharing is a control the account holder sets, not a crawl invitation to Search. It does not imply Chat or Health are ad inventory; Search-and-ads keeps ads off those apps. It does not claim the publisher site is free of ads; selected finished pages may show Google ads, disclosed in Privacy and Cookies.
It also does not invent scale theater. No fake user counts. No launch-hype swagger. Just the published path: public links in, private stores out.
## Discovery without credentials
A useful stress test asks what the crawler can obtain with no account cookie and no special operator privilege. If the answer is a normal public HTML response, the URL is a candidate for public-link discovery, subject to robots rules and rate limits. If the answer is nothing useful until someone signs in, the URL is a private store edge, not a crawl seed.
That test keeps engineering honest when product hosts share design language. A landing page that explains Health can be public; the note list behind sign-in cannot. A Chat product description can be public; the thread transcript cannot. Drive’s overview can be public; the file bytes cannot. Account help copy can be public; the settings row cannot. Following public links only ever applies to the first half of each pair. Ranking then scores that public half against a query. Equal results for equal queries stay coherent because the corpus was never a per-user private vault.
## Editorial discipline on the same theme
What we publish says the recovery from thin promotional stubs is a smaller, stricter public index of real documents. Journal essays about Search corpus rules belong there: they add a method and a boundary. The method here is link-following on the public web. The boundary is private product data. If an older sentence ever implied Search could see everything in an Oernoe account, that sentence should be corrected in public. Follow public links, not private stores, is the corrected shape.
## Closing the loop
Follow public links. Index public pages and approved listings. Rank those documents against queries without turning query history into an advertising profile. Leave Health notes, Chat threads, Drive files, and account settings where they belong: behind account controls, off the crawler’s path. That is the Search corpus story we will stand behind, and it is smaller than the brand’s total surface on purpose.
O
Oernoe Editorial Team
Writes for the Oernoe Journal. Questions about this article can go to the contact page.
Get in touchRelated Articles
Want to Learn More?
Explore our complete guides and knowledge base for more insights on privacy, technology, and best practices.
Browse Our Guides