privacy

DeepSeek Collects More Than Your Prompts

DeepSeek collects keystroke patterns, chat history, and device data, all stored on servers in China. Here's what the privacy policy actually says.

DeepSeek arrived in early 2025 as a surprise: a high-performance AI model from a Chinese company that outperformed much larger Western competitors at a fraction of the cost. Its chatbot app rapidly climbed the download charts in dozens of countries. And then the questions started.

What exactly does DeepSeek collect? Where does that data go? And what does Chinese law mean for users outside of China?

The answers are all in DeepSeek’s own documentation — and they’re worth reading carefully before you type anything sensitive into that chat window.


What DeepSeek Explicitly Collects

DeepSeek’s privacy policy, last updated in February 2026, is unusually detailed about what it gathers. Here’s the actual list from the policy:

  • Chat history and prompts — everything you type and every response generated
  • Account information — email, username, and any profile details you provide
  • Device identifiers — hardware model, operating system, unique device IDs
  • Network information — IP address, carrier, and network type
  • Keystroke patterns and rhythms — specifically listed as behavioral data collected during use
  • Location data — coarse location derived from IP, or precise location if the app is granted permission
  • Browsing behavior within the app — how you navigate, what you tap, how long you pause on a response

The keystroke patterns entry is the one that catches most researchers off guard. This kind of typing rhythm data — sometimes called “keystroke dynamics” — is used in behavioral biometrics systems. It can be used to identify individuals even without direct identifying information. Its inclusion in a chat app’s collection list is unusual and has no clear purpose in the context of an AI assistant.


Where All of This Goes

DeepSeek stores collected data on servers located in the People’s Republic of China. This is not a minor detail.

Under Chinese law — specifically the National Intelligence Law of 2017 and the Data Security Law of 2021 — companies operating in China are required to cooperate with state intelligence investigations. If the Chinese government requests access to data held by a Chinese company, that company is legally obligated to comply. The company’s practical ability to refuse is effectively zero.

This is distinct from a company being secretly malicious. A company can have entirely legitimate intentions and still be subject to legal obligations that override those intentions. The jurisdiction of the data matters, not just the intent of the company holding it.

For users in most Western countries, this creates a risk profile that doesn’t exist with European or US-hosted services. Your prompts, your typing patterns, and the personal context you provide to DeepSeek are governed by Chinese law, regardless of where you are in the world when you type them.


The Database Exposure

In early 2025, security researchers at Wiz discovered a publicly accessible DeepSeek database containing over one million records. The database was reachable without authentication — no login required to access sensitive data.

The exposed records included chat logs, system prompts, API keys, and backend operational data. The issue was resolved after the researchers notified DeepSeek, but the incident revealed a gap in the company’s infrastructure security practices. A database containing user interactions should not be publicly reachable under any circumstances.

A separate finding from mobile security researchers identified code in the DeepSeek iOS app transmitting data to a server operated by China Mobile, a state-controlled telecommunications company. China Mobile has been barred from operating in the United States by the Federal Communications Commission. The presence of that code in a consumer app, sending data without user awareness, raised immediate and specific concerns about the scope of what was being transmitted and why.


Government Bans

Several countries moved quickly to restrict DeepSeek in government contexts following these findings:

  • Italy banned DeepSeek from operating in the country, citing insufficient transparency about data handling practices
  • Australia issued a government-wide ban on DeepSeek across all government devices
  • Taiwan restricted its use on government-issued devices over national security concerns
  • South Korea temporarily suspended the app from local app stores pending a privacy review

These bans apply specifically to government use, not consumer use. But the reasons cited — Chinese data jurisdiction, transparency gaps, and the database exposure — are the same reasons that apply to any user, not just government officials. The distinction between “banned for government” and “safe for everyone else” is a legal one, not a technical one.


Model Safety and What It Signals

Separate from data collection, multiple security research teams found that DeepSeek’s content safety guardrails were significantly easier to bypass than those of comparable Western models. Testing found that attempts to get the model to produce restricted content succeeded at unusually high rates.

This matters indirectly for privacy because it’s a signal about operational priorities. Companies that invest heavily in safety testing, access controls, and policy compliance tend to also invest heavily in secure data handling. A model whose safety systems fall apart under basic adversarial testing may reflect broader gaps in the company’s security culture, not just its content policies.


What This Means for Personal Content

If you’re using DeepSeek to draft generic emails or write code that doesn’t contain personal details, the risk profile is similar to using any cloud-based AI tool — with the important distinction of Chinese jurisdiction.

If you’re feeding it personal files, medical records, legal documents, financial details, or anything you wouldn’t want stored indefinitely on servers subject to Chinese government access — the calculus is different.

AI chat interfaces feel conversational and ephemeral. You type something, you get a response, and it feels like a conversation that ends. But the prompts you submit are data. That data is being stored, according to DeepSeek’s own policy, for as long as the company considers it necessary.

This is why the storage layer for personal content matters independently of which AI tool you use for a given task. Keeping your personal files, notes, and memories in a service you trust — one that is transparent about where your data lives, under what legal framework, and with what encryption — insulates that content from the AI tools you happen to use to process it.

The prompt you type to an AI is one data point. The underlying files you’re working with are another. The tool that processes a document doesn’t have to be the same as the service where that document lives. Keeping them separate is a straightforward way to limit exposure.


The Alternatives Question

For users who want to continue using capable AI models but want their personal data — notes, files, memories — stored somewhere with a cleaner data profile, the separation is practical.

Use whatever AI tool fits the task. Keep your personal content in a storage service that operates under a legal jurisdiction you understand, with clear data retention policies, and without financial incentives to monetize your content. The two choices are independent.

For reference: daftei stores files using AES-256 encryption at rest and TLS 1.3 in transit, operates under GDPR and CCPA, never trains third-party AI on user content, and never sells data. Files are yours and stay yours. Pricing starts at 5 GB free.


The Bottom Line

DeepSeek is a capable AI model with a detailed privacy policy that tells you, in plain text, exactly what it collects. That transparency is more than most apps offer.

But transparency about extensive collection isn’t the same as privacy. Knowing that DeepSeek records typing patterns, stores chat history on Chinese servers, and operates under laws that require cooperation with government intelligence requests — that’s useful information. The database breach and the mobile code transmitting data to a state company add concrete evidence to what the policy describes in abstract terms.

Whether you use DeepSeek is a choice based on your specific needs and risk tolerance. Understanding what you’re agreeing to when you do is the minimum requirement for making that choice deliberately.

Your memories deserve better than an ad platform.

Try daftei free →
← All posts