DeepSeek Privacy Policy Explained: What Data Does DeepSeek Collect?

Last reviewed: May 16, 2026

DeepSeek’s Privacy Policy applies to personal data processed in connection with DeepSeek apps, websites, software, and related services that link to or reference the policy. It does not govern personal data collected from end users of downstream systems or applications built by developers using the DeepSeek Open Platform.

For services covered by the policy, DeepSeek says it may collect account details, prompts, uploaded files, photos, voice inputs, feedback, chat history, device and network data, usage logs, approximate location, and information from certain third-party services. The policy also states that DeepSeek directly collects, processes, and stores personal data for those covered services in the People’s Republic of China.

For an API-backed application, the application operator’s privacy notice, architecture, account settings, caching behavior, logging practices, and contract must be reviewed separately. DeepSeek’s public documents do not provide one universal zero-retention, data-residency, or no-training guarantee for every downstream integration.

Disclaimer: This article is for general information only and is not legal advice. Privacy rights, compliance duties, and risk levels can vary by country, industry, and use case.

Quick Answer: What Data Does DeepSeek Collect?

For the DeepSeek services covered by its Privacy Policy, DeepSeek describes three broad sources of personal data: information users provide, information collected automatically, and information received from other sources. Depending on the service and features used, this may include account information, prompts, text or voice inputs, uploaded files, photos, feedback, chat history, IP address, device identifiers, operating system information, usage and performance logs, approximate IP-based location, and information from third-party sign-in or security services.

This list describes the DeepSeek services covered by the policy. It should not be presented as a complete description of what every downstream API application collects. A downstream application must provide its own privacy notice and explain its own collection, retention, sharing, and deletion practices.

Key Takeaways

  • DeepSeek’s Privacy Policy covers DeepSeek services that link to or reference the policy.
  • For those covered services, DeepSeek describes personal data provided by users, collected automatically, and received from other sources.
  • User input may include prompts, uploaded files, photos, feedback, voice input, and chat history.
  • The policy states that personal data for covered services is directly collected, processed, and stored in the People’s Republic of China.
  • The policy expressly excludes personal data collected from end users of downstream applications built through the DeepSeek Open Platform.
  • Developers operating downstream applications must publish their own privacy disclosures and establish an appropriate legal basis for processing.
  • The “Improve the model for everyone” setting should not be described as a universal API no-training or zero-retention commitment.
  • Users should not submit sensitive personal data, credentials, confidential files, regulated records, or trade secrets to an unapproved AI service.

What Is the DeepSeek Privacy Policy?

The DeepSeek Privacy Policy is the document that explains how DeepSeek processes personal data related to its services. DeepSeek says the policy applies to personal data processed in connection with DeepSeek apps, websites, software, and related services that link to or reference the policy. It also identifies Hangzhou DeepSeek Artificial Intelligence Co., Ltd. as the data controller for the services covered by the policy.

One important limitation is that DeepSeek’s policy does not automatically cover personal data collected from end users when they access downstream systems or applications built by developers using DeepSeek’s open platform services. In those cases, the developer operating the downstream application is expected to disclose its own privacy policy.

What Data Does DeepSeek Collect?

According to the current DeepSeek Privacy Policy, DeepSeek data collection is divided into three main categories: data you provide, data automatically collected when you use the service, and data received from other sources.

Data categoryExamplesHow DeepSeek may use itPrivacy concern
Account personal dataDate of birth where applicable, username, email address, phone number, passwordAccount creation, login, support, security, policy enforcementAccount identifiers can connect your activity to a real person
User inputText input, voice input, prompts, uploaded files, photos, feedback, chat history, other content provided to the modelGenerate outputs, provide the service, improve services, support model or technology improvementPrompts and files may contain sensitive personal, business, or confidential information
Support/contact dataProof of identity or age, contact details, feedback, inquiries, reports of policy violationsCustomer support, identity verification, policy enforcement, legal complianceSupport messages may include private context users disclose voluntarily
Device and network dataDevice model, operating system, IP address, device identifiers, system language, device ID, user IDSecurity, login continuity, diagnostics, fraud prevention, service operationDevice identifiers and IP data can help track usage across sessions or devices
Log and usage dataFeatures used, actions taken, service interaction logsAnalytics, troubleshooting, service improvement, safety monitoringUsage logs can reveal behavior patterns and interests
Location dataApproximate location based on IP addressAccount security, unusual-login detection, location-related answersLocation is not precise by default, but approximate location can still be sensitive
Cookies and similar technologiesSession cookies, preference cookies, security cookies, support cookiesSecurity, login/session management, preferences, support functionalityCookies can create persistent browser-level identifiers
Payment data for paid open platform servicesPayment order and transaction informationOrder placement, payment, customer service, after-sales supportPayment metadata may reveal business or usage relationships
Third-party login dataAccess token or related data from Apple, Google, or linked servicesLogin, signup, account linkingThird-party login can connect DeepSeek use with other identity providers
Security partner dataFraud, abuse, or security-threat signals from trusted partnersSafety, abuse prevention, account protectionSecurity-related sharing may involve automated risk signals
Publicly available dataPublic online personal data DeepSeek says it may obtainModel training and service provisionPublic information can still be personal data, depending on jurisdiction

DeepSeek says the services are not designed or intended to process sensitive personal data, including information related to race or ethnicity, religious beliefs, health, sexuality, citizenship, immigration status, genetic or biometric data, children, precise geolocation, or criminal membership. The policy says users should not provide sensitive personal data to the services.

Does DeepSeek Collect Your Prompts, Files, Photos, and Chat History?

Yes. According to DeepSeek’s policy, when you use the service, DeepSeek may collect your text input, voice input, prompt, uploaded files, photos, feedback, chat history, or other content you provide to the model and services. DeepSeek calls these “Prompts” or “Inputs,” and says it generates “Outputs” based on them.

This matters because prompts are often more revealing than people expect. A prompt can include a private medical question, a draft contract, a client email, source code, a spreadsheet, a business plan, a school record, a personal dispute, or a document containing someone else’s personal data.

DeepSeek also says it will not extract or mine voiceprint, facial recognition information, or other unique biological patterns from voice inputs or photos provided by users. That is a useful limitation, but it does not mean voice inputs or photos are never collected or processed.

Does DeepSeek Use Your Data to Train Its AI Models?

For the services covered by DeepSeek’s Privacy Policy and Terms of Use, DeepSeek says personal data, Inputs, and Outputs may be used to provide, maintain, develop, or improve its services and underlying technologies. Its Terms describe an opt-out setting called “Improve the model for everyone” for the model-improvement processing described there.

This consumer-facing setting should not be presented as a universal contractual no-training commitment for every API account or downstream application. API developers and business customers should verify which settings and terms apply to their specific account, whether any separate contractual commitment exists, and whether other processing continues for service delivery, security, legal compliance, caching, abuse prevention, or account operation.

Turning off a model-improvement setting does not itself delete previous chats, erase cached or logged data, or stop processing needed to provide and secure the service. Training, retention, chat-history deletion, API caching, and account deletion are separate issues.

Where Is DeepSeek Data Stored?

For the DeepSeek services covered by its Privacy Policy, DeepSeek states that personal data may be stored outside the user’s country and that it directly collects, processes, and stores personal data in the People’s Republic of China.

This statement should not be automatically extended to every downstream API application or self-hosted deployment. An API-backed data flow may involve the application operator, DeepSeek’s Open Platform, server-side logs, disk caching, analytics, and other infrastructure. The precise processing location, retention period, and contractual safeguards must be verified for the specific integration.

For a self-hosted model, data location depends on the organization’s own infrastructure, logs, backups, observability tools, network egress, and access controls.

Who Can DeepSeek Share Your Data With?

DeepSeek says it may share personal data with service providers, corporate-group entities, and other third parties in limited scenarios. Service providers may support functions such as customer inquiries, communications, search services, analytics, support, and safety monitoring. DeepSeek also says it integrates third-party APIs to provide search services and may share input keywords to provide those services.

DeepSeek also says corporate-group entities may process personal data for functions such as storage, content delivery, security, research and development, foundation model training and optimization, analytics, customer support, and technical support.

Other sharing scenarios include corporate transactions, legal requests, public authorities, law enforcement, rights holders, emergency situations, policy enforcement, and user-authorized sharing. DeepSeek’s Terms and Privacy Policy also warn that shared conversation links can be viewed by anyone with the link and may be exposed to third parties if published on public networks.

The policy also says DeepSeek does not engage in targeted advertising, does not “sell” personal data, and does not use personal data for profiling or automated processing that produces legal or similarly significant effects.

How Long Does DeepSeek Keep Your Data?

For services covered by its Privacy Policy, DeepSeek does not publish one fixed retention period for every category of personal data. It says retention depends on the purpose, type and sensitivity of the data, legal requirements, service delivery, account status, safety, security, legitimate business interests, and legal claims.

That consumer-policy wording should not be treated as a complete API retention schedule. DeepSeek’s API documentation separately states that Context Caching on Disk is enabled by default and that an unused cache is usually cleared within a few hours to a few days. This cache statement is not a universal retention or deletion guarantee for every API record, log, account record, or downstream application.

Unless an applicable account setting or written contract says otherwise, API users should not promise immediate deletion, zero retention, or a fixed retention period for all DeepSeek API Inputs and Outputs.

Can You Delete DeepSeek Data or Opt Out?

DeepSeek says users may have privacy rights depending on where they live, including rights to know whether and how their personal data is processed, access personal data, correct inaccuracies, delete personal data, receive a portable copy, and opt out of certain processing. The Privacy Policy specifically includes the right to opt out of using personal data for training models or optimizing technologies.

DeepSeek also says users can manage some personal data through settings, including managing, copying, or deleting chat history. If a user deletes their account, DeepSeek says the account cannot be reactivated and content or personal data connected with the account cannot be retrieved.

For privacy requests, DeepSeek lists privacy@deepseek.com. For users in the European Union and United Kingdom, the policy also identifies Prighter as a privacy representative and gives rep_deepseek@prighter.com as a data-subject-request contact.

To reduce model-training use, check whether your account has the “Improve the model for everyone” setting and turn it off if you do not want your Inputs and Outputs used in the way described in the Terms of Use.

DeepSeek App Privacy: Apple App Store and Google Play Labels

Apple’s App Store privacy label for DeepSeek says the developer indicated that the app’s privacy practices may include data handling described on the page, and Apple notes that this information has not been verified by Apple. Apple also says privacy practices may vary based on factors such as the features you use or your age.

According to the Apple App Store label, data linked to users may include location, contact information, user content, search history, identifiers, usage data, and diagnostics. The label lists examples such as coarse location, email address, phone number, photos or videos, customer support content, other user content, search history, user ID, device ID, product interaction, crash data, performance data, and other diagnostic data.

Google Play’s Data Safety section says data privacy and security practices may vary based on use, region, and age, and that the developer provides the information. For DeepSeek, Google Play says the app may share Device or other IDs, may collect Location, Personal info and 5 others, encrypts data in transit, and allows users to request data deletion.

App-store labels are useful summaries, but they are not a substitute for reading the official DeepSeek Privacy Policy and Terms of Use. They are also not the same as an independent privacy audit. Apple notes that the privacy information is provided by the developer and may not have been independently verified by Apple, so it should be treated as a store-label summary rather than a full privacy audit.

DeepSeek Privacy Concerns and Regulatory Scrutiny

DeepSeek privacy risks have attracted attention from several regulators and governments, especially around transparency, cross-border transfers, training data, and data stored in China.

In Italy, the Garante requested information from DeepSeek about the personal data collected, its sources and purposes, the legal basis for processing, whether data was stored on servers in China, and what information was used to train the AI system.

Two days later, the Italian Data Protection Authority ordered an urgent limitation on processing Italian users’ data against Hangzhou DeepSeek Artificial Intelligence and Beijing DeepSeek Artificial Intelligence, saying the companies’ response was considered unsatisfactory, and it opened an investigation.

In South Korea, the Personal Information Protection Commission said DeepSeek temporarily suspended its app service in Korea as of February 15, 2025, to improve compliance with the Personal Information Protection Act. The PIPC said its analysis found third-party data-transfer traffic and insufficient transparency in DeepSeek’s privacy policy, and it advised existing users to avoid entering personal information until the examination was complete.

The PIPC later reported that DeepSeek’s initial Korean launch had insufficient transparency, including lack of detail on destruction procedures, safeguards, and chief privacy officer information. It also said DeepSeek had transferred personal data to servers in China and the U.S. without separate consent or disclosure at launch, and that DeepSeek added opt-out features for user-entered data used in AI development and training.

In Germany, the Berlin Commissioner for Data Protection and Freedom of Information notified Apple and Google in Germany of the DeepSeek app as illegal content, citing alleged unlawful transfer of personal data to China. The commissioner said DeepSeek processed extensive personal data, including text entries, chat histories, uploaded files, location, device, and network data, and transferred collected user data to Chinese processors and servers in China.

Reuters reported in January 2026 that DeepSeek had come under scrutiny in multiple countries for security policies and privacy practices, and summarized actions or reviews involving countries including Australia, Czech Republic, France, Germany, India, Italy, the Netherlands, South Korea, Taiwan, and the United States.

This does not mean DeepSeek is banned everywhere or unsafe for every use. It means users should treat DeepSeek as a tool that requires context-specific privacy judgment, especially when using it for work, confidential projects, regulated data, or personal information.

Is DeepSeek Safe to Use?

Casual users

For casual brainstorming, translation, summaries of non-sensitive public text, learning, or general productivity, DeepSeek may be usable if you avoid entering private information. The main risk is not ordinary casual use; it is accidentally pasting sensitive or identifiable content into prompts, files, photos, or chat history. DeepSeek itself says users should not provide sensitive personal data.

Privacy-conscious users

Privacy-conscious users should be more cautious because the policy allows collection of prompts, files, photos, chat history, device data, usage logs, approximate location, and data from other sources. They should also consider the policy’s statement that personal data is directly collected, processed, and stored in China.

Businesses

Businesses should not use consumer AI chatbots for confidential work without a vendor-risk review. DeepSeek’s policy and Terms make clear that user inputs, files, and outputs can be processed to provide and improve the service, and its data-storage language raises cross-border transfer questions for many organizations.

Developers

Developers should avoid pasting proprietary source code, credentials, API keys, secrets, customer logs, unreleased product details, or regulated datasets into DeepSeek unless their organization has approved that workflow. DeepSeek’s Privacy Policy also says downstream applications built on its open platform are not covered by the same policy for end-user personal data, so developers need their own privacy disclosures for their apps.

Regulated industries

Healthcare, legal, finance, education, insurance, government, defense, and other regulated sectors should be especially cautious. DeepSeek’s Terms warn that outputs should not be treated as professional advice and should not be the basis for actions or omissions in medical, legal, financial, or other professional contexts.

How to Use DeepSeek More Privately

Use this checklist before entering anything into DeepSeek:

  • Do not enter passwords, API keys, private keys, session tokens, or login codes.
  • Do not upload passports, national IDs, tax documents, bank statements, contracts, medical records, or school records.
  • Do not paste confidential work files, trade secrets, unreleased product plans, private customer data, or proprietary source code.
  • Avoid entering names, addresses, phone numbers, emails, or identifying details unless truly necessary.
  • Turn off “Improve the model for everyone” if you do not want your Inputs and Outputs used for the processing described in DeepSeek’s Terms.
  • Delete individual chats or chat history when you no longer need them, while remembering that policy-based retention may still apply.
  • Do not create public shared links for private conversations.
  • Use a separate email address if you want to reduce account-linking risk.
  • Review DeepSeek’s Privacy Policy and Terms periodically because DeepSeek says it may update its policies and services.
  • For business use, consider enterprise controls, local deployment of open-source models, approved AI gateways, or a formal vendor-risk assessment.

DeepSeek Privacy Policy: Pros, Cons, and Red Flags

AreaProsCons / red flags
TransparencyPolicy identifies categories of data collected and names the controllerThe policy covers broad categories, including prompts, files, photos, and chat history
User rightsLists access, deletion, correction, portability, and opt-out rights where applicableRights depend on location and may be subject to exceptions
Model trainingTerms mention an opt-out setting for “Improve the model for everyone”Users must understand and actively manage the setting
StorageDeepSeek clearly discloses that data may be stored outside the user’s countryThe policy says data is directly collected, processed, and stored in China
Sensitive dataPolicy tells users not to provide sensitive personal dataUsers may accidentally submit sensitive information in prompts or uploaded files
App-store labelsApple and Google Play provide privacy summariesStore labels are developer-provided summaries, not full legal or technical audits
SharingSharing categories are described, including service providers and legal requestsCorporate-group processing and third-party service providers can expand the data-processing ecosystem
RegulatorsRegulatory scrutiny gives users more public information to considerItaly, South Korea, and Germany raised privacy or transfer concerns

FAQ

What data does DeepSeek collect?

DeepSeek collects account data, prompts, text and voice inputs, uploaded files, photos, feedback, chat history, contact/support data, IP address, device identifiers, device model, operating system, usage logs, approximate location from IP address, cookies where applicable, payment data for paid open-platform services, third-party login data, security partner data, and public data.

Does DeepSeek store data in China?

For DeepSeek services covered by its Privacy Policy, DeepSeek states that it directly collects, processes, and stores personal data in the People’s Republic of China. This statement does not establish the complete data-residency architecture of every downstream API application, third-party provider, or self-hosted deployment.

Does DeepSeek read my prompts?

DeepSeek processes prompts and inputs to generate outputs. Its policy says it may collect text input, voice input, prompts, uploaded files, photos, feedback, chat history, and other content provided to its model and services.

Does DeepSeek use my chats to train AI models?

For services covered by its Privacy Policy and Terms, DeepSeek says personal data, Inputs, and Outputs may be used to improve services or underlying technologies. Its Terms describe an “Improve the model for everyone” opt-out setting. Users should not assume that this setting applies identically to every API account or that it creates a universal zero-retention commitment.

Can I opt out of DeepSeek model training?

DeepSeek describes an opt-out from certain model-improvement processing through the “Improve the model for everyone” setting. Check whether that setting is available for the exact product and account you use. API and downstream-application users should verify applicable terms and contractual commitments separately.

Can I delete my DeepSeek chat history?

DeepSeek says users can manage chat history through settings and may copy or delete chat history via settings. However, deleting visible chat history should not be treated as a guarantee that every related record is immediately removed from all systems, because the policy also describes retention for service, legal, security, and business purposes.

Can I delete my DeepSeek account?

Yes. DeepSeek says users may delete their account, but if they do, they cannot reactivate the account or retrieve content or personal data connected with that account. DeepSeek’s Terms also say certain data may still be retained as required by laws and regulations or for prior violations.

Is DeepSeek safe for business data?

DeepSeek’s public consumer services should not be used for confidential or regulated business data without formal approval. An API integration must be assessed separately based on its data flow, caching, logs, retention, security controls, application privacy notice, and contract. A self-hosted deployment may provide greater control but is not automatically secure or compliant.

Is DeepSeek safe for personal information?

It is safer if you avoid entering personal information. DeepSeek says its services are not designed or intended to process sensitive personal data and tells users not to provide it.

What should I avoid entering into DeepSeek?

Avoid sensitive personal data, medical information, legal matters, financial records, passwords, IDs, confidential work files, trade secrets, customer data, private source code, children’s data, and anything you would not want processed, stored, or reviewed under the policy. DeepSeek’s own policy warns against providing sensitive personal data.

Does DeepSeek collect location data?

DeepSeek says it automatically collects approximate location based on IP address for security and some location-related responses. It says it will not obtain precise geolocation through other means without explicit consent.

Does DeepSeek share data with third parties?

Yes. DeepSeek says it may share personal data with service providers, corporate-group entities, parties to corporate transactions, law enforcement or public authorities where legally required or necessary, and other third parties with user consent or authorization.

Conclusion

The DeepSeek Privacy Policy is relatively clear about the big categories of data DeepSeek collects: account details, prompts, uploaded content, chat history, device data, logs, approximate location, third-party login data, and some data from security partners or public sources. The biggest privacy issues are not hidden: DeepSeek says user inputs and outputs may be used to improve services or technologies, users need to manage the “Improve the model for everyone” setting if they want to opt out of that described processing, and DeepSeek says it directly collects, processes, and stores personal data in China.

For casual, non-sensitive use, DeepSeek may be acceptable if you treat it like any online AI tool and avoid sharing private information. For business, regulated, legal, medical, financial, government, or confidential use, DeepSeek should go through a proper privacy, security, and compliance review before employees or developers paste data into it.