Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Meilisearch is an open source search engine built by a French company that powers fast site and application search. It can be fully self hosted on your own infrastructure or run on Meilisearch Cloud with a region of your choice, so personal data never has to leave the EU. By default it sets no third party tracking cookies, which makes it a privacy friendly alternative to hosted search services. Optional anonymous telemetry can be switched off completely.
Meilisearch is an open source search engine that delivers fast, typo tolerant search for websites and applications. It is developed by a company headquartered in Paris, France, and the core engine is released under an open source license so you can run it yourself. You can self host it on your own servers in any region, or use the managed Meilisearch Cloud and pick a server location that suits your data residency needs. Because the engine runs server side and exposes a search API, the search itself does not require any tracking cookies in the visitor browser. This design makes Meilisearch a strong choice for organisations that want powerful search while keeping a small privacy footprint. It is widely used as a self hosted, privacy friendly alternative to fully hosted search products.
By default the Meilisearch engine sets no third party tracking cookies on your visitors. A front end search widget may store a small value in localStorage or use a session token to remember recent queries or display preferences, which is first party and not used for advertising. The engine processes the search queries that users type and the documents you index, which can contain personal data depending on what you choose to make searchable. The open source build includes optional anonymous telemetry that reports aggregated usage metrics to the maintainers, and this can be disabled with a single environment variable. Meilisearch Cloud may collect operational logs needed to run the managed service. You remain in control of what is indexed and how long search logs are retained.
Under the ePrivacy Directive, consent is required for storing or reading information on a device unless it is strictly necessary for a service the user requested. Because Meilisearch sets no advertising cookies and any local storage it uses serves the search the visitor asked for, a default deployment usually falls under the strictly necessary or legitimate interest path. The personal data you index and the search queries you log are processed under the GDPR, with you acting as the data controller. If you self host, Meilisearch is simply software you operate, so there is no external processor for the search function. If you use Meilisearch Cloud, the company acts as a processor and you should put a data processing agreement in place. Keeping the configuration cookieless greatly simplifies your ePrivacy position.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
For a standard cookieless search deployment you generally do not need a consent banner gate in front of the search box, since the processing is strictly necessary or based on legitimate interest. You should still describe the search functionality in your privacy notice and explain any local storage used by the search widget. If you layer optional analytics, heatmaps, or marketing tags around the search experience, those require prior opt in consent and should be wired into your consent management platform. A clean approach is to keep search outside the consent gate and only block the truly optional extras until the visitor agrees. Always disable the engine telemetry if you do not want any usage data leaving your environment. Document your reasoning so you can demonstrate accountability to a regulator.
When you self host Meilisearch on servers located in the European Union, personal data stays within the region you control and there is no transfer to a third country. Meilisearch Cloud lets you select a region, so you can keep data inside the EU if that is your requirement. The company behind Meilisearch is based in France, which is inside the EU, reducing exposure to third country transfer concerns. If you enable anonymous telemetry, only aggregated and non identifying metrics are sent, and you can turn this off entirely. For organisations with strict data residency obligations, the self hosted EU model offers the cleanest path with no onward international transfer. Always confirm the hosting region of any cloud option before going live.
Start by choosing where to run Meilisearch and, for EU users, prefer self hosting or an EU region so data residency is clear. Disable anonymous telemetry if you do not want any usage metrics leaving your environment. Review what you index and avoid placing unnecessary personal or special category data into searchable documents. Set a sensible retention policy for search logs and restrict access to the admin API keys. Update your privacy notice to mention the search engine, the legitimate interest or strictly necessary basis, and any first party local storage used by the widget. If you use Meilisearch Cloud, sign a data processing agreement and record the region. Finally, keep your cookie and privacy documentation in sync with the actual configuration whenever you change it.
Websites using Meilisearch must obtain user consent under GDPR regulations.
DPIA considerations
A self hosted EU deployment of Meilisearch is generally low risk and rarely triggers a mandatory Data Protection Impact Assessment, because no third party tracking cookies are set and no personal data is transferred to a third country. A DPIA may still be warranted if you index special category data, large volumes of personal records, or combine search logs with user identifiers. Document the data you index, retention of search logs, and whether anonymous telemetry is enabled. If you use Meilisearch Cloud, record the chosen region and the processor relationship.
Sample consent text
This website uses Meilisearch to provide search. Search runs on our own EU servers and sets no advertising or third party tracking cookies. We may store a small preference locally in your browser to improve your search experience.
Third-party domains contacted
meilisearch.comedge.meilisearch.comcloud.meilisearch.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| No tracking cookies | none | n/a | By default Meilisearch sets no third party tracking cookies in the visitor browser. The search itself runs server side through an API. |
| localStorage search preference | first_party | persistent until cleared | A front end search widget may store recent queries or display preferences locally in the browser to improve the search experience. This is first party and not used for advertising. |
Meilisearch collects user analytics data — you legally need a consent banner. Try FlowConsent free.
By default a self hosted Meilisearch deployment sets no third party tracking cookies. A front end search widget may store a small value in localStorage or use a session token to remember recent queries or display preferences, which is first party and not used for advertising. Meilisearch Cloud keeps operational logs but does not place tracking cookies on your visitors.
For a standard cookieless search deployment you generally do not need prior consent, because the processing is strictly necessary for the search the visitor requested or relies on legitimate interest. You only need consent if you add optional analytics, marketing tags or non essential cookies around the search experience.
The usual legal basis is legitimate interest under GDPR Article 6(1)(f) for providing site search the visitor asked for, or strictly necessary processing where search is core to your service. Any optional analytics layered on top would require consent under Article 6(1)(a).
No transfer to the United States is required. When self hosted in the EU, data stays in your chosen region, and Meilisearch Cloud lets you select an EU region. The company is based in France, and the only optional outbound data is anonymous telemetry that you can disable entirely.
A self hosted EU deployment is generally low risk and rarely triggers a mandatory Data Protection Impact Assessment. A DPIA may still be warranted if you index special category data, large volumes of personal records, or combine search logs with user identifiers.
Host it in the EU or pick an EU cloud region, disable anonymous telemetry if you want no outbound metrics, and avoid indexing unnecessary personal data. Set a retention policy for search logs, secure the admin API keys, and describe the search function in your privacy notice.
Meilisearch is already a privacy friendly, self hostable option. Comparable engines include Typesense and OpenSearch, which can also be self hosted in the EU, or Algolia as a hosted alternative that involves more third party processing. Choosing any self hosted EU option keeps data residency under your control.
State that search is powered by Meilisearch, note that it sets no third party tracking cookies by default, and describe any first party local storage used by the search widget. If you use Meilisearch Cloud, mention the region and the processor relationship, and review the entry whenever you change the configuration.