Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Apisearch is an open source search engine that powers site search and can be self hosted on your own infrastructure or consumed as a cloud service. A JavaScript widget or script sends each visitor search query to the Apisearch backend and can set a cookie or a browser storage entry to hold the search session and to record search analytics such as the terms typed and the results clicked. Because search terms can be personal data, any non essential search analytics must load only after the visitor has given consent.
Apisearch is an open source search engine that powers the search box on a website. It can be self hosted on infrastructure that you control or consumed as a managed cloud service. The search experience runs as a JavaScript widget or script that loads on the page and sends each query that a visitor types to the Apisearch backend, which returns matching results in real time.
When a visitor runs a search, the widget sends the typed query to the Apisearch backend and can record search analytics such as the terms entered, the number of results returned and which results were clicked. To keep a single search session together and to attribute these analytics, Apisearch can set a first party cookie or a browser storage entry on the visitor device. Search queries themselves can be personal data, because a person may type a name, an email address, a health concern or another detail that relates to an identifiable individual.
Search queries and the identifiers used to group them are personal data under the GDPR when they relate to an identifiable visitor. Reading from or writing to the visitor terminal to store a search session or an analytics entry falls within Article 5(3) of the ePrivacy Directive, which the CNIL in France, the German authorities under the TDDDG and the AEPD in Spain enforce as a strict prior consent obligation for any storage that is not strictly necessary to deliver the service the visitor asked for.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Consent is required before Apisearch sets any non essential cookie or storage entry, such as one used for search analytics, because that processing is not strictly necessary to return search results. The consent must be freely given, specific, informed and unambiguous, and refusing must be as easy as accepting. A strictly functional query box that simply returns results, without writing analytics storage, can rely on the necessity exemption and can run without consent.
Whether Apisearch transfers data outside the European Economic Area depends on how it is deployed. If you self host Apisearch on servers located inside the European Union, search queries stay within the European Economic Area and no third country transfer occurs. If you use the Apisearch cloud service, or host on infrastructure outside the European Economic Area such as United States based regions, search queries are transferred to a third country and must be covered by the EU Standard Contractual Clauses together with a documented Transfer Impact Assessment in line with the Schrems II ruling.
Decide whether you need search analytics at all; if you only need a functional query box, disable analytics so that no non essential storage is used and no consent is needed. Where you do use analytics, gate the Apisearch widget behind your consent management platform so it fires only after the relevant category is accepted. Prefer a self hosted deployment inside the European Union to avoid international transfers, describe the session and analytics cookies in your cookie policy, apply a short retention period to query logs and, if you rely on the cloud service, sign the data processing terms and complete a Transfer Impact Assessment.
Websites using Apisearch must obtain user consent under GDPR regulations.
DPIA considerations
A Data Protection Impact Assessment is advisable when Apisearch processes large volumes of search queries that can reveal interests, health, financial or other sensitive matters, or when search behaviour is linked to identifiable users. Document the search queries collected, the session and analytics cookies or storage entries set by the widget, the retention applied to query logs, and whether the deployment is self hosted inside the European Union or relies on a cloud service that transfers data to a third country. Where only a strictly functional query box is needed, disable search analytics so that no non essential storage is used.
Sample consent text
We use Apisearch to power the search box on this site. When you run a search, your query is sent to the Apisearch backend and a cookie or storage entry may be set to keep your search session and to measure search performance. If Apisearch is provided as a cloud service, your query may be transferred outside the European Economic Area under the EU Standard Contractual Clauses. Search analytics will only load if you click Accept.
Third-party domains contacted
apisearch.ioCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| apisearch_session | HTTP cookie (first party) | Session | Keeps a single search session together so that the queries and interactions of one visit are grouped and attributed consistently. This cookie is set by the Apisearch widget or by your own server when Apisearch is self hosted. |
| apisearch_analytics | localStorage | Persistent (until cleared) | Stores search analytics such as the queries typed, the number of results returned and the results clicked, so that search performance can be measured. This non essential entry requires prior consent and can be disabled when only a functional query box is needed. |
Apisearch collects user analytics data — you legally need a consent banner. Try FlowConsent free.
Apisearch can set a first party session cookie that keeps a single search session together and a browser storage entry that holds search analytics such as the queries typed and the results clicked. A strictly functional query box can be configured without analytics storage, in which case no non essential entry is set.
Yes. When Apisearch writes a non essential cookie or storage entry for search analytics, the ePrivacy rules require prior consent before that storage is set. A purely functional query box that only returns results, without analytics storage, can run under the necessity exemption without consent.
For non essential search analytics the legal basis is consent under Article 6(1)(a) GDPR, combined with the prior consent requirement of Article 5(3) of the ePrivacy Directive. A strictly functional search box that is necessary to deliver the service the visitor requested can rely on the necessity exemption instead.
It depends on how you deploy it. A self hosted Apisearch inside the European Union keeps search queries within the European Economic Area. The Apisearch cloud service, or hosting on United States based infrastructure, transfers queries to a third country and needs the EU Standard Contractual Clauses and a Transfer Impact Assessment.
A Data Protection Impact Assessment is recommended when Apisearch processes search queries at scale or when queries can reveal sensitive matters linked to identifiable users. Assess the query logs, the session and analytics storage, the retention period and any transfer to a third country.
Decide whether you need analytics; if not, run a functional query box only. Where you use analytics, load the widget through your consent management platform after the relevant category is accepted, prefer a self hosted deployment inside the European Union, describe the cookies in your cookie policy and apply a short retention to query logs.
Alternatives include Meilisearch, Typesense, Elasticsearch, OpenSearch and Algolia. Each raises similar query, storage and transfer questions, so evaluate the hosting location and data processing terms before assuming any of them is lighter on privacy.
Add a dedicated entry that names Apisearch, lists the session and analytics cookies or storage entries with their lifetimes, explains the search analytics collected, and, if you use the cloud service, discloses the transfer outside the European Economic Area and its safeguard. Keep the entry aligned with your consent categories.