Search that keeps queries on the device.
Sprigr hosts your records and compiles them into an index the browser downloads once. Keyword queries are then answered locally, so the text your users type is not sent to Sprigr or to your server. Semantic mode and analytics are opt-in, and you can see exactly what each one transmits.
Your records are hosted on Cloudflare, isolated per tenant. The browser downloads a compiled index once and answers keyword queries locally, so the query text is not sent to Sprigr. Analytics are optional and off unless you post events. You decide what, if anything, leaves the device.
You focus on the work. Sprigr runs the paperwork.
- Keyword queries stay in the browser
- Analytics off by default
- Isolated per tenant
- Never trained on
What actually happens to the data
The honest version: what stays on the device, what is hosted, and which switches you control.
-
Keyword queries never leave the browser
In client-side mode the WebAssembly engine loads your compiled index and scores, filters, and highlights every keyword query locally. No per-search request is made, so neither Sprigr nor your own server sees the query text.
-
Semantic mode is explicit
Hybrid semantic search needs an embedding for each query, which the browser fetches from
/1/embed. That call carries the query text. It only happens on indexes where you enablesemantic_searchand passsemantic: true, so the trade-off is yours to make per index. -
Analytics are opt-in
Nothing is recorded about searches unless your page posts events to
/1/events. If you do, those events (query text, clicked object, and an optional user token) are stored server-side so you can see popular queries and click-through rates. Leave the endpoint unused and there is nothing to report and nothing to delete. -
Records hosted on Cloudflare
The data you index is stored on Cloudflare infrastructure, isolated per tenant and reachable only with your API keys. Scoped keys carry a locked filter the engine applies to every query, so a key minted for one end user can never widen its own access.
-
No cookies or fingerprinting
The engine sets no cookies and does no fingerprinting. It runs in memory; whether the downloaded index is cached between visits is up to the HTTP caching headers you serve it with.
-
Never trained on, deleted on request
Sprigr never trains models on your data. Delete an object, an index, or your account and the data is removed within 30 days. See the privacy policy for the full retention terms.
Search queries can reveal a lot about a person. The fewer parties that see them, the less you have to document and defend. Client-side keyword mode keeps queries on the device by design; everything that does leave the browser is a choice you make in configuration, not a default you have to discover.
Read the privacy policy →Questions
Does Sprigr see what my users search for?
In client-side keyword mode, no: the query is scored in the browser and no request is made per search. Two things change that. Hybrid semantic mode sends each query to /1/embed to get an embedding, and analytics events, if your page sends them, include the query text. Both are off unless you turn them on. If you use the server-side REST API instead of client-side mode, every query is a request to Sprigr and is handled under the privacy policy.
Where is my data stored?
Indexed records live on Cloudflare infrastructure, isolated per tenant. They are the data you push through the REST API or MCP tools. Sprigr does not sell them and never trains models on them. The privacy policy covers processing locations and retention.
Does Sprigr set cookies or track users for search?
No. The engine sets no cookies, does no fingerprinting, and keeps no per-user search history. The optional analytics endpoint accepts a user token if you choose to supply one; if you do not, there is no per-user record.
Does client-side mode reduce my GDPR workload?
It reduces the number of parties that see query text. In keyword mode the query never leaves the device, so there is no search-query processing by Sprigr to document. You still host records with Sprigr, so treat Sprigr as a processor for that data and cover it in your records of processing. This page is not legal advice; check the obligations that apply to your data with your own adviser.
What about cross-border transfers?
Keyword queries in client-side mode are not transferred anywhere. Your indexed records are hosted on Cloudflare and subject to Cloudflare's data-location commitments; the privacy policy describes where Sprigr processes data. Do not assume there are no transfers for the records themselves.
Privacy-first search, ready in minutes.
Paid plans from $49 a month.