Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Typesense Work in China? PIPL Cross-Border, Data Residency & Self-Hosting

Typesense is an open-source, self-hostable search engine that also does vector search: the documents you index and the embeddings derived from them are personal information held at rest, and Typesense Cloud has no mainland-China region — so indexing your China users' data there is a PIPL cross-border transfer. A compliance-first look at the residency exposure and the in-country self-host lever.

Does Typesense work in China?

The documents you index into Typesense — and the embeddings it derives from them — are personal information that sits at rest wherever the engine runs, and Typesense Cloud has no mainland-China region.

Typesense is a search engine (with vector and semantic search) that stores the documents you load into it plus dense-vector embeddings built from the same text; for China users that content is personal information. Indexing it into an offshore Typesense Cloud region is a PIPL cross-border transfer and a residency problem — and embeddings do not launder it, since they can be inverted back toward the source text and sit beside their payload. The lawful lever is to keep the index and embeddings in-country by self-hosting the open-source, GPL-3.0 engine (or a licensed in-country managed deployment), not to make the offshore endpoint reachable.

This is a risk map, not a verdict — settle the specifics with counsel. Our China team can map your exposure →

What Typesense's own documentation says about China

FactPrimary source
Typesense is open source under the GPL-3.0 license and self-hostable as a single binary. Its GitHub repository lists the GPL-3.0 license and describes Typesense as “a fast, typo-tolerant search engine,” noting it is “a single binary that you can run locally or in production with a single command” — so the same engine can run on in-country infrastructure, keeping the index and embeddings on the mainland. Typesense, GitHub repository (github.com/typesense/typesense), retrieved 2026-10-10
Typesense Cloud runs in 25+ geographic regions worldwide — none inside mainland China. Typesense's own Search Delivery Network documentation states “Typesense Cloud has 25+ geo regions around the world,” spanning the Americas, Europe, the Middle East and Asia-Pacific (for example Oregon, Ohio, Northern Virginia, Frankfurt, London, Singapore, Tokyo, Seoul and Sydney), with no mainland-China location — so a China-facing Cloud cluster holds your index offshore. Typesense Docs, “Search Delivery Network” (typesense.org), retrieved 2026-10-10
Indexing China-user data into an offshore store is a PIPL cross-border transfer, with an in-country storage duty for CIIOs and high-volume handlers. Under PIPL Articles 38–40, transferring personal information abroad requires notice, a separate consent, and one transfer mechanism; the Cybersecurity Law Article 39 (formerly Article 37) requires critical information infrastructure operators to store China-collected personal information in the mainland. Personal Information Protection Law (PIPL) Arts. 38–40; Cybersecurity Law Art. 39 (formerly Art. 37), 2025 amendment effective 2026-01-01; retrieved 2026-10-10
Embeddings and query logs are personal information too — and large transfers may need a security assessment. A vector embedding is computed from the source text and supports inversion and membership inference, so it carries the same residency duties as the raw data; sizable cross-border transfers may trigger China's data-export security assessment (数据出境安全评估). China Data Export Security Assessment Measures (CAC), effective 2022-09-01; retrieved 2026-10-10

Sources verified by the 21YunBox compliance team on 2026-10-10.

For a mainland-China audience, whether Typesense “works” is settled before anyone measures a query: it turns on where the content you index is allowed to live. A search engine is a data-at-rest store — you load Typesense with the documents you want searchable (records, profiles, support-ticket text), and it keeps them, builds an inverted index, and, with vector and semantic search on, stores dense-vector embeddings computed from that text. For a China-facing product those documents describe people, so both the index and the embeddings hold personal information. Helpfully, Typesense is open source under the GPL-3.0 license and ships as a single, self-hostable binary — but its managed service, Typesense Cloud, has no mainland-China region, so indexing your China users’ data there puts that content, and its embeddings, offshore. Three prongs decide the rest: cross-border transfer of the indexed content, embeddings that are themselves personal information, and the lever of self-hosting the open engine in-country.

Typesense's GitHub repository page showing the GPL-3.0 license and the README describing Typesense as a fast, typo-tolerant, self-hostable single-binary search engine
"Typesense is a fast, typo-tolerant search engine for building delightful search experiences." Typesense's own repository publishes it under the GPL-3.0 license and as a single self-hostable binary — the engine you can run in-country. Source: Typesense on GitHub

Typesense in China at a glance

What decides it In Typesense's own terms — and China's law
What you load into it You index full documents — names, emails, order histories, ticket text — into Typesense collections, and with vector/semantic search on, it also stores embeddings built from that text. Both are personal information held at rest, not a cache.
Where the engine runs Typesense's own docs state "Typesense Cloud has 25+ geo regions around the world" — across the Americas, Europe, the Middle East and Asia-Pacific, none inside mainland China. Indexing China-user data into any of them is a cross-border transfer (数据出境) under PIPL Articles 38–40.
Embeddings are personal information A vector is computed from the source text and supports inversion (reconstructing approximate text) and membership inference, so it is not anonymous. "We only send vectors" does not take an index of your users' data outside PIPL.
Data residency A critical information infrastructure operator or high-volume handler must store China-collected personal information in the mainland — Cybersecurity Law Article 39 (formerly Article 37) — which no offshore region can satisfy. Your query logs carry the same weight.
The axis — and the lever Reachability is not the question. Because Typesense is GPL-3.0 open source and self-hostable as a single binary, the lawful lever is to run the engine in-country so the index and embeddings stay on the mainland; the app querying it still needs an ICP filing and in-country delivery.

What you actually store — indexed content and its embeddings

A search engine is not a pipe; it is a store. When you index into Typesense you hand it the full documents you want searchable, and in practice those documents carry names, email addresses, phone numbers, order histories, support-ticket text, and whatever else your users generate. Typesense keeps that content in its collections, on disk, and builds an inverted index over it so lookups are instant. Turn on its vector and semantic search and it stores something further: dense-vector embeddings computed from the same text, kept alongside the original fields. Self-hosted, all of this lives in the engine’s on-disk data directory on the machine you run; on Typesense Cloud, it lives in the cluster’s region. Either way, the question “where does my China users’ personal information rest?” is answered by “wherever the Typesense data directory is” — not by how fast a query returns. That is why reachability is the wrong axis: the store, and the personal information inside it, has a location, and that location is what the law reads.

It’s a residency and cross-border-transfer problem — and embeddings don’t anonymize it — under PIPL

Once you accept that the index is your users’ personal information, the governing law follows. Index documents collected from people in mainland China into a Typesense cluster that sits in any of Typesense Cloud’s offshore regions, and you have carried personal information across the border — a cross-border transfer (数据出境) under China’s Personal Information Protection Law. The handler — you, not Typesense — must give notice, obtain a separate consent for the transfer, and clear one transfer mechanism: a CAC security assessment, the CAC standard contract, or certification (Articles 38–40). If you are a critical information infrastructure operator or a high-volume handler, personal information collected in China must additionally be stored in the mainland — Cybersecurity Law Article 39 (formerly Article 37) (the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged) — a residency duty no offshore region can satisfy.

The distinctive trap is the embedding. It is tempting to think that keeping “only vectors” launders the data — that an array of floating-point numbers is anonymous. It is not. An embedding is computed directly from the source text and is kept precisely because it preserves that text’s meaning; published research shows embeddings support inversion (reconstructing approximate source text) and membership inference (telling whether a given record was in the set). A store of embeddings of your China users’ documents is therefore itself a store of their personal information, with the same residency and cross-border duties as the raw text — and in Typesense the payload fields usually sit right beside the vector, so the original data is there too. Your query logs carry the same weight: the terms your users type are personal information about what they are looking for. None of this is a reason to stop using Typesense; it is a reason to decide, deliberately, where the store lives.

Reaching the endpoint isn’t the question — keeping the index in-country is

Typesense Cloud is reachable, and the self-hosted binary installs in a single command; connectivity was never the obstacle. The obstacle is residency, and the honest fix is to keep the index and its embeddings on the mainland rather than to make an offshore store reachable. Because Typesense is open source under the GPL-3.0 license and runs as a self-contained binary — via its official Docker image, native binaries, or DEB/RPM packages — you can run the exact same engine on in-country infrastructure, so the collections, the inverted index, and the embeddings never leave China. Minimize and pseudonymize what you index while you are at it: a field you never put into a document is a field you never have to transfer. Where a managed, in-country deployment is available through a licensed local operator, that can be a lawful option too — but treat it as a warn-positive to confirm, naming the operator precisely, not as a global pass. What none of this is: shipping the data to an offshore store and calling it local. Localizing means the data-at-rest store genuinely sits on an in-country path.

This is a risk map, not a verdict: whether a localization duty applies, which cross-border mechanism fits, and how much of your index counts as personal information turn on your entity, your data volumes, and whose data it is — settle the specifics with counsel before you build.

The lawful path — map, localize, deliver

Map. We inventory what you index and vectorize, what personal information those documents carry, whether embeddings of personal data are stored, where the engine runs today (a Typesense Cloud region, or self-hosted), your query-log exposure, and the consent basis behind it all.

Localize. We keep your China-user indexed content and embeddings in-country — standing up the open-source Typesense engine on mainland infrastructure so the collections, index, and vectors stay on the mainland, or using a managed in-country deployment via a licensed local operator where that fits — then minimize and pseudonymize what is indexed and govern any residual cross-border transfer. 21YunBox never uses or suggests circumvention of any kind.

Deliver. The application that queries the index still faces the public in China, so it carries an ICP filing duty and needs compliant, in-country delivery — the 21YunBox Optimizer, set in front of the stack you already run, with no rebuild and no migration. Typesense stays your search engine; we add the lawful China boundary around it so it runs legally and compliantly for your users in China.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Is Typesense available in mainland China?
Typesense Cloud's endpoints are reachable and the self-hosted binary installs anywhere, so availability is not the obstacle. The real question for a China-facing product is data residency: Typesense Cloud has no mainland-China region, so the documents you index and the embeddings derived from them sit offshore. Self-hosting the open-source engine in-country keeps that index and those embeddings on the mainland. Treat the specifics as a risk to confirm with counsel.
Are the embeddings in Typesense personal data under PIPL?
Yes, when they are built from your China users' content. A vector embedding is computed from the source text and can be inverted back toward it or used for membership inference, and in Typesense the raw payload usually sits beside the vector — so an index of embeddings of your users' documents is itself a store of their personal information, with the same cross-border and residency duties as the original text. “We only send vectors” is not anonymization.
Can I run Typesense compliantly for China users?
Yes. Because Typesense is GPL-3.0 open source and self-hostable as a single binary, you can run the engine on in-country infrastructure so the collections, index, and embeddings stay on the mainland, minimize and pseudonymize what you index, and deliver the querying app on ICP-filed infrastructure. 21YunBox maps that exposure, stands up the in-country self-hosted engine, and delivers the app in-country — settle the specifics with counsel.

ARTICLES RELATED TO TYPESENSE

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.