Knowledge · Is this AI tool safe · 8 minutes

Is DeepSeek safe? The app, the open model and your company data

Where DeepSeek stores your chats, whether it trains on them, what Italy, Poland and Berlin regulators did, and how the app differs from a model you run locally.

Last updated: October 5, 2026

Is the DeepSeek app safe, or is it about the model itself?

The name DeepSeek covers two different things. The first is a service: the mobile app, the chat.deepseek.com website and the paid API, run by the Chinese company Hangzhou DeepSeek Artificial Intelligence Co., Ltd. The second is the open-weights models, model files that anyone can download and run on their own hardware.

The risks differ. With the service, the question is what the provider does with your data and who can access it. With a model you run yourself, data stays in your infrastructure, but questions about answer quality and resistance to attacks remain.

arLET'S does not issue a "safe" or "unsafe" verdict. Below is what is known from the provider's documents and regulators' decisions, with dates and sources, and what is not known.

What does DeepSeek do with the data you type in?

According to the DeepSeek privacy policy (last updated 10 February 2026), the company collects, among other things, your prompts, uploaded files, chat history, and device and network data. This data may be used to train and improve its models. Among the rights that may apply depending on where you live, the policy lists the right to opt out of the use of your data for model training, and it takes requests at privacy@deepseek.com. It does not describe an in-app toggle, so check whether your version has one.

Retention: data needed to provide the service, including chat history, is kept for as long as you have an account. You can copy and delete your history in settings. The policy does not say plainly what happens to data after you delete your account.

Personal versus business plans: in DeepSeek's published documents we found no business plan for the chat and no separate data processing agreement (DPA). For the API, the privacy policy only states that it does not cover end users of apps built on the platform; the developer is responsible for them. This differs from providers that switch off training by default for business customers, as described in our article is ChatGPT safe.

Where does DeepSeek process data, and on what legal basis?

The privacy policy states directly that DeepSeek collects, processes and stores personal data in the People's Republic of China. Data may go to service providers (analytics, communications, search) and to group companies, including for model training.

The policy names Prighter Group as its representative in the EU and the UK. As legal bases for EEA users it lists performance of a contract, consent and legitimate interests. It does not name a mechanism for transfers to China, such as standard contractual clauses; it only refers to appropriate safeguards in general terms.

China has no European Commission adequacy decision. Poland's data protection authority (UODO) pointed this out on 6 February 2025, adding that the Chinese government has broad powers to access personal data without the safeguards provided for in EU law.

How to limit the risk if you use DeepSeek: step by step

1. Decide whether you need the service at all. If you need the model rather than the app, run the open weights locally or with a cloud provider in the EU. DeepSeek-R1 is released under the MIT licence, which permits commercial use.

2. Do not sign in with a work account, and do not enter personal data, client data, code containing secrets or internal documents. We cover the limits in can you paste data into ChatGPT; the same rules apply to DeepSeek.

3. Opt out of training: email privacy@deepseek.com, and check whether your version of the app has a settings toggle that shares your chats to improve the model.

4. Delete your chat history in settings regularly. When you stop using the service, delete the account.

5. If you pasted an API key or a .env file by accident, treat it as exposed and rotate it. You can identify what you pasted locally in your browser, without sending it anywhere.

Known incidents and regulator actions

29 January 2025: Wiz Research described a publicly reachable ClickHouse database belonging to DeepSeek, with no authentication. It held over a million log lines, including chat history and API keys. According to Wiz, DeepSeek secured it promptly after being notified.

30 January 2025: Italy's data protection authority (Garante) ordered an urgent limitation on processing Italian users' data by both DeepSeek companies and opened an investigation. The companies replied that they had not entered the Italian market, had removed the app from Italian stores and were not subject to the GDPR; the authority held that the GDPR applies because the service was offered to people in the EU.

6 February 2025: the President of UODO advised far-reaching caution when using the DeepSeek app and other DeepSeek services, and said the office was in contact with other European Data Protection Board (EDPB) authorities about DeepSeek's activities in the EU.

27 June 2025: the Berlin Commissioner for Data Protection reported the DeepSeek app to Apple and Google as illegal content under Article 16 of the Digital Services Act (DSA), because of data transfers to China. Earlier, on 6 May 2025, it had asked the company to withdraw the app or meet the transfer requirements.

9 July 2025: the Czech cyber security agency NUKIB issued a warning for entities covered by the Czech Cyber Security Act and rated the threat as high. The warning explicitly excludes open-source models run locally with no connection to DeepSeek servers.

30 September 2025: the Center for AI Standards and Innovation (CAISI) at the US NIST published an evaluation of R1, R1-0528 and V3.1, compared with selected US models. According to CAISI, agents built on R1-0528, the most secure of the DeepSeek models tested, were on average 12 times more susceptible to hijacking than the US reference models, and R1-0528 answered 94% of overtly malicious requests when a common jailbreaking technique was used (US models: 8%).

When does DeepSeek make sense for a business, and when does it not?

The DeepSeek app or website makes sense at a company at most for tasks on public data, without a work account. It does not make sense where personal data, trade secrets or client data are involved, or where the company falls under cyber security rules such as NIS2. Transfers to China need a basis under Article 46 GDPR; on 27 June 2025 the Berlin data protection authority found that DeepSeek infringes Article 46(1) GDPR.

The open model makes sense when you want to run it yourself or with an EU provider, under a contract you control. Test it on your own tasks before deployment, especially if it will act as an agent with access to tools, because the CAISI evaluation at NIST points to a susceptibility to hijacking.

If staff already use DeepSeek on their own, that is classic shadow AI. Rather than a bare ban, add DeepSeek to your company AI use policy and name a tool people are allowed to use. You can also check any AI tool's website for free and see which third-party services the website itself passes data to. This check does not cover the mobile app or what happens to data on the provider's servers.

What we do not know

It is not known on which specific legal mechanism DeepSeek relies to transfer data from the EU to China; the policy does not name one. It is not known how long data remains after account deletion, or whether an opt-out covers data already used for training.

As of October 2026 we found no public information that the Garante data protection proceedings have concluded, nor about the outcome of the work coordinated through the EDPB. We also found no ban on DeepSeek in Polish public administration; there is a UODO statement advising caution.

For comparison, we ran the same set of questions for other tools: Copilot and Gemini. Current as of October 2026.

In short

  • The DeepSeek app and website store data in China and, under the policy dated 10 February 2026, may train models on it; you opt out by email.
  • DeepSeek's documents show no business plan for the chat and no DPA, so company and personal data should not go there.
  • EU regulators acted: the Garante limited processing (30 Jan 2025), UODO advised caution (6 Feb 2025), Berlin reported the app to the stores (27 Jun 2025).
  • An open DeepSeek model run locally sends no data to DeepSeek, but test it on your own tasks before using it as an agent.

Have a website, app or email address that looks suspicious?

Frequently asked questions

Is DeepSeek safe?

It depends on the form. The app and website store chats in China and may train on them, and Poland's data protection authority advised caution. An open-weights model run on your own hardware sends no data to DeepSeek.

Is the DeepSeek app safe?

The app sends your prompts, files and device data to servers in China. Italy limited its data processing in January 2025, and in June 2025 the Berlin data protection authority reported it to Apple and Google as illegal content.

Does DeepSeek train its models on my chats?

The privacy policy dated 10 February 2026 allows data to be used to train and improve models. You can opt out by emailing privacy@deepseek.com.

Is DeepSeek banned in Poland?

We found no such ban. On 6 February 2025 the President of UODO advised far-reaching caution when using the DeepSeek app and services.

Can DeepSeek be used safely on a local machine?

A model run on your own hardware with no connection to DeepSeek servers sends no data to the provider; the Czech agency NUKIB excluded this case from its warning. Model-level risks remain, such as the agent hijacking susceptibility reported by CAISI at NIST.

Sources

  1. DeepSeek: Privacy Policy (updated 10 Feb 2026)
  2. Personal Data Protection Office (UODO): UODO recommends caution when using DeepSeek (6 Feb 2025)
  3. Italian Data Protection Authority (Garante): Order of 30 January 2025 [10098477]
  4. Berlin Commissioner for Data Protection: press release on DeepSeek (27 Jun 2025)
  5. Czech National Cyber and Information Security Agency (NUKIB): Warning about certain DeepSeek products (9 Jul 2025)
  6. Wiz Research: Exposed DeepSeek Database Leaking Sensitive Information (29 Jan 2025)
  7. NIST: CAISI Evaluation of DeepSeek AI Models Finds Shortcomings and Risks (30 Sep 2025)
  8. Hugging Face: deepseek-ai/DeepSeek-R1 (MIT licence)

Accurate as of the article's last update. Laws and vendor terms change, so check the source before you decide.

See also