Not with confidential data through DeepSeek's own app or website. Its privacy policy says personal data is stored in the People's Republic of China and kept "as long as necessary", and app chats can train its models unless you opt out. DeepSeek's open-weight models are a different matter: run on your own hardware or by a cloud host, DeepSeek never sees your data.
So "is DeepSeek safe?" has no single answer, because four different things share the name: a consumer app and website, a developer API, model files you can download and run yourself, and those same models run for you by a cloud provider such as Amazon Bedrock. The first sends everything you type to DeepSeek under consumer terms; the last two send nothing to DeepSeek at all. Most of the risk comes from staff using the free app for work without anyone deciding whether they should.
Four different things called DeepSeek
| Route | Whose terms apply | Where your text goes | Can it train on your input? | For client data? |
|---|---|---|---|---|
| DeepSeek app or website | DeepSeek's privacy policy and terms of use | DeepSeek's servers; the policy says data is stored in the People's Republic of China | Yes, after de-identification, unless you switch off "Improve the model for everyone" | No |
| DeepSeek API | DeepSeek's Open Platform terms | DeepSeek's servers; the terms don't state a location or retention period | The terms give DeepSeek no right to use your inputs to improve its models | Only after written answers on retention and location |
| Open weights on a cloud host | The host's terms, such as AWS for Bedrock | The host's data centres, in the region you choose | Governed by the host; AWS says model providers can't see your prompts | Possible, like any hosted model |
| Open weights on your own machine | The model licence only (MIT) | Nowhere; it stays on the computer | No | Yes, with normal device security |
The first row is the one most staff actually use, and it's where DeepSeek's own documents say the most.
What DeepSeek's own policy and terms say, clause by clause
These are the points in DeepSeek's documents that matter to a business, from the privacy policy last updated on 10 February 2026 and the terms of use last updated on 27 March 2026. Both cover the app and website; I'd reread them before relying on any of this, because both have changed within the year.
- Where data lives. The policy says DeepSeek directly collects, processes and stores personal data in the People's Republic of China. The service is run by Hangzhou DeepSeek Artificial Intelligence Co., Ltd.
- What counts as your data. Text and voice input, prompts, uploaded files, photos, feedback and chat history, plus device model, IP address, device identifiers and approximate location based on IP address.
- Training. The terms say inputs and outputs may be used to develop and improve the service after encryption processing and "strict de-identification". You can opt out by switching off "Improve the model for everyone"; the policy also describes a right to opt out by contacting DeepSeek.
- How long it's kept. "As long as necessary to provide our Services" and for the policy's other purposes, including legal obligations and legitimate business interests. No fixed period is given.
- Who else sees it. Companies in DeepSeek's corporate group, for purposes that include storage, security, and training and improving its foundation models, plus law enforcement or public authorities where DeepSeek believes it's necessary to comply with applicable law.
- Voice and photos. The policy says DeepSeek won't extract voiceprints or facial recognition information from voice input or photos you upload.
- Which law governs disputes. The laws of the People's Republic of China, with disputes going to a court where DeepSeek's registered office is.
- What's reassuring. The policy states DeepSeek doesn't engage in targeted advertising or sell personal data, and the terms assign you whatever rights exist in the outputs.
Set that beside the business plans most small firms would otherwise use and the gap is clear:
| Question | DeepSeek app | ChatGPT Business or Claude Team |
|---|---|---|
| Trains on your content by default? | Yes, unless each user opts out | No |
| Who controls the settings? | Each person, inside their own consumer account | An admin, for the whole workspace |
| Governing law for disputes | The People's Republic of China | Set out in the vendor's business terms; check them for your contract |
| Price | Free | From $20 a seat a month billed annually, minimum 2 seats |
The opt-out lives in each person's own account, so an owner has no way to enforce it or check it. That, more than any single clause, is why the app doesn't suit client work: you can't manage what you can't see. What to check in an AI tool's privacy policy and terms gives a general method for reading documents like these.
What changes when you use the API instead of the app
Developers usually reach DeepSeek through its API, because it's cheap. Its pricing page lists the Flash model at $0.30 per million input tokens and $1.20 per million output tokens at peak times, with off-peak rates half that. The API sits under a separate document, the DeepSeek Open Platform Terms of Service (effective 29 April 2026), and it reads differently from the app's terms:
- It contains no clause giving DeepSeek the right to use your API inputs or outputs to improve its models, and says neither party's rights transfer to the other.
- It states no retention period for API calls and doesn't say where API traffic is processed.
- Your own account details as a developer fall under the privacy policy above, stored in the People's Republic of China.
- If you build something customers use, section 3.3 puts the duty on you to tell those end users how their personal information is processed, get their consent, and respond to their access and deletion requests.
So the API is better than the app on training and still silent on the two questions a business most needs answered: how long your data is kept and where it's processed. Until DeepSeek answers those in writing, assume API traffic is handled on DeepSeek's own infrastructure under the same jurisdiction as the app.
The price argument is also weaker than it looks. Picture a 14-person engineering consultancy that wants 5,000 archived project emails, averaging 400 words, sorted into categories. That's roughly 2.7 million input tokens, with a short label out for each email, about 100,000 output tokens:
| Option | Listed price (input / output per million tokens) | Cost of the job |
|---|---|---|
| DeepSeek API, Flash model, peak | $0.30 / $1.20 | About $0.93 |
| DeepSeek v3.2 hosted on Amazon Bedrock | $0.62 / $1.85 | About $1.86 |
| OpenAI API, gpt-5-nano | $0.05 / $0.40 | About $0.18 |
Every option costs less than a coffee. At this scale the choice turns entirely on the data terms, and OpenAI's API doesn't train on API data by default, while the Bedrock route keeps the model provider out of it altogether. Being cheap is no reason to accept the least clear terms.
Written questions to send before any API use on client data
If a developer or supplier wants to run anything more sensitive than public text through DeepSeek's API, get answers in writing first. The Open Platform terms leave these points open, so the answers are what you'd be relying on. An email you can adapt:
Subject: Data handling questions before we use the DeepSeek API
Before we send any business data through the DeepSeek API, please
confirm in writing:
1. How long are API inputs and outputs retained, and can we choose
zero retention?
2. In which country or countries are API requests processed and
stored?
3. Are API inputs or outputs ever used to train or improve models,
or reviewed by people? If so, how do we opt out?
4. Which other companies, including companies in your group, can
access API data, and for what purposes?
5. Will you sign a data processing agreement with us?
6. How, and how quickly, would you tell us about a security
incident affecting our data?
[Your name], [business name]
How to read the replies you might get:
- A stated retention period with a zero-retention option, a named processing location, a plain "no training, no human review" and a signed agreement. You can then treat the API like any other provider, subject to what your own client contracts allow.
- A link back to the privacy policy. That adds nothing, because the policy covers the app and says data is kept "as long as necessary". Ask again, pointing to the specific question.
- Silence after two weeks. That's an answer too. Use the hosted or local route below instead.
File whatever comes back with the date. If a client ever asks where their data went, that file is your answer, and it's what a data-protection adviser will ask to see first.
Using DeepSeek's open models without sending DeepSeek anything
DeepSeek publishes its model weights under the MIT licence, which allows commercial use. That gives two routes where DeepSeek receives nothing.
On your own computer. DeepSeek's flagship models are enormous: the DeepSeek-V4.1-Flash page lists 763 billion parameters, and the full DeepSeek-R1 in the Ollama library is a 404GB download. What people run on office hardware are the distilled versions, smaller Qwen and Llama models trained to imitate DeepSeek-R1's reasoning. The Ollama library lists them from a 1.1GB download up to 43GB, with the 14b version at 9GB and 32b at 20GB. Two things follow. These are good small models rather than the DeepSeek you'd get in the app, so test them on your own work; and their licences come from the base model, Apache 2.0 for the Qwen versions and the Llama 3.3 licence for the 70b. Running AI on your own computers covers the hardware and setup.
Through a cloud host. Amazon Bedrock runs DeepSeek models on AWS's own infrastructure. Its documentation says model providers have no access to Bedrock logs or to customer prompts and completions, and Bedrock offers a zero-retention mode for models that allow it. The data question then becomes whether you trust AWS's terms, the same question as for any model it hosts. The open-model licences and trade-offs are compared in more depth in open-source versus paid AI models.
The security record so far
Policies describe intentions; incidents show practice. In January 2025, Wiz Research reported finding a publicly accessible DeepSeek database, open without any authentication, containing more than a million lines of logs including chat history and API secrets. DeepSeek secured it promptly once told. One incident doesn't make a service unsafe, and larger providers have had lapses too, but it's a reminder that "stored securely" depends on the provider's engineering as well as its promises. Several governments have also barred the DeepSeek app from official devices, citing data security. Neither fact decides anything for a small firm on its own. Both belong in the balance when a free app is weighed against a business plan that costs $20 a seat.
Sorting your data before anyone opens the app
The practical rule is to decide by the data, not the tool. Here's a filled-in sorting table for a nine-person architect practice:
| Data | Example | DeepSeek app? | Better route |
|---|---|---|---|
| Public | Rewording the practice's published project descriptions | Acceptable with training switched off | Any assistant |
| Internal, not sensitive | A generic checklist for site visits | Acceptable with training switched off | The practice's business plan |
| Client personal data | Homeowner names, addresses, contact details | No | A business plan with no training by default |
| Confidential client work | Drawings and specifications under an NDA | No | A local model, or no AI |
| Credentials and finance | Planning portal logins, fee schedules, bank details | Never | Never into any chat tool |
The rows at the bottom are why the "it's only a quick question" habit is the real risk. A realistic before-and-after from a surveying firm shows the difference. Before, a surveyor pastes this into the app:
Summarise this email chain about the dispute with [client full name]
at [full property address] over the damp report. Their solicitor's
letter is below, plus our invoice with our bank details.
That prompt hands over a named client, an address, a live legal dispute and the firm's bank details. After, with the parts that identify anyone removed:
Summarise the main points of disagreement in this correspondence
between a homeowner (Client A) and a surveying firm (Firm B) about
a damp survey. Names, addresses and financial details are removed.
List each point of disagreement and what each side says about it.
The second version gets almost the same useful summary with nothing that matters to a stranger. It's still better done in a business plan, but it shows the habit to teach; anonymising client data before you paste it into AI covers the technique properly.
A painter and decorator, an accountant and an engineer: three verdicts
The painter and decorator wants help with social posts, a price-list layout and polite replies to review sites. Nothing is confidential. The app is workable with "Improve the model for everyone" switched off, and so is any other free assistant; the reason to pick DeepSeek over the alternatives would be preference, not need.
The accountancy practice handles client financial records, identity documents and tax affairs every day. Its professional duties of confidentiality make the app a poor fit, and a per-user opt-out nobody can audit doesn't meet the standard its clients expect. It should use a business plan that doesn't train by default, and write a one-line rule banning the DeepSeek app for client work.
The engineering consultancy wanted DeepSeek because a developer said its models were strong and cheap. It can have the models without the data exposure by running a hosted DeepSeek model on Bedrock for the email-sorting job, or a distilled version locally for NDA projects. The cost table above shows the API's price advantage is pennies either way.
A staff rule for DeepSeek, ready to paste
If staff are already using the app, and in many small firms someone is, banning it without an alternative just drives the use out of sight. Give them the rule and the approved route in the same message. A filled-in version:
DEEPSEEK AND OTHER FREE AI APPS: OUR RULE Updated: [month, year]
- For client work, use [approved business plan]. Ask [first name]
for a seat if you don't have one.
- The DeepSeek app and website: allowed ONLY for public or generic
material (marketing wording, general questions), with
"Improve the model for everyone" switched off.
- Never paste client names, addresses, documents, drawings,
financial details or logins into the DeepSeek app or any free app.
- Developers: no DeepSeek API use on client data without written
sign-off from [first name]. Hosted versions (e.g. on Bedrock)
or local models are the approved way to use DeepSeek's models.
- Unsure whether something is sensitive? Treat it as sensitive.
If someone has already pasted client material into the app, don't start with blame; start with facts. Ask what went in and roughly when, and write it down. Have them switch off "Improve the model for everyone" straight away so nothing further is used for training. If client personal data was involved, speak to your data-protection adviser or solicitor about whether the client needs to be told or anything needs reporting, because that depends on what was shared and the law that applies to you. Then move that person's work onto the approved route the same day, so the fix is easier than the habit.
Pair the rule with a quick check a month later: ask staff which AI tools they've used that week, without blame, and see whether the approved route is actually easier than the app. If it isn't, fix the route rather than repeating the rule. Stopping staff pasting client data into free tools covers that wider problem across every app, not just this one.
Further reads
- Cloud AI vs On-Device AI: Which Is Safer for Business Data? — The general case for keeping sensitive work on your own devices.
- How to Stop AI Tools Training on Your Business Data — Switch off training on every AI tool your staff use, not just one.
- Does ChatGPT Train on Client Data? Business vs Free Plans — How ChatGPT's business and free plans compare on the same questions.
- What to Check in an AI Vendor's Data Processing Agreement — What to ask for before client data goes into any AI service.
- How to Classify Business Data Before Using AI Tools — Sort your files into tiers before choosing where each may go.
- Is Gemini Safe for Confidential Business Data in Workspace? — The same safety question answered for Gemini in Workspace.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: DeepSeek Privacy Policy (last updated 10 February 2026), DeepSeek Terms of Use (last updated 27 March 2026), DeepSeek Open Platform Terms of Service (effective 29 April 2026) and DeepSeek API pricing page; DeepSeek-R1 and DeepSeek-V4.1-Flash model pages; Ollama library page for deepseek-r1; Amazon Bedrock documentation (data protection, data retention) and pricing; Wiz Research report on the exposed DeepSeek database (January 2025).