Last reviewed
The short answer. DeepSeek is a poor fit for company data unless the company has accepted its terms. Its privacy policy says it collects prompts, files, and chat history, stores data in the People’s Republic of China, and uses data to train its models. Italy’s data protection authority and Texas have restricted it.
That makes DeepSeek a data leakage question before it is a model quality question. The guide to stopping data leaking into AI covers the general rule: decide which tools may receive company data, and keep everything else out of them.
What DeepSeek collects
The privacy policy covers “DeepSeek apps, websites, software, and related services.” Applications that other developers build on its open platform are outside it. As of 2026-10-10, the policy shows a last update of February 10, 2026 and lists these categories (DeepSeek Privacy Policy):
- Inputs. Text and voice input, prompts, uploaded files, photos, feedback, and chat history.
- Account data. Email address or telephone number, username and password, and date of birth where applicable.
- Device and network data. IP address, device identifiers, device model, operating system, and cookies, with approximate location taken from the IP address.
- Usage logs. The features used and the actions taken.
Anything an employee types or uploads is an input. A contract, a customer list, or source code pasted into a prompt becomes data DeepSeek collects.
Where DeepSeek stores and processes data
The policy states that DeepSeek will “directly collect, process and store your Personal Data in People’s Republic of China.” It also says data may be stored on a server outside the country where you live (DeepSeek Privacy Policy). The controller named in the policy is Hangzhou DeepSeek Artificial Intelligence Co., Ltd., with a registered address in China.
Where a company is bound by rules on where data may be stored or who may access it, this section decides the question. Contracts, client agreements, and regulations that restrict cross-border transfers apply to a prompt in the same way they apply to a file.
Training, retention, and sharing
Training. The policy lists using data “to train and improve our technology, such as our machine learning models and algorithms.” It also lists a right to opt out of using personal data for training. It gives no settings path for that right, and requests go by email to the address in the policy (DeepSeek Privacy Policy). The policy as read on 2026-10-10 does not describe a business plan with different training terms.
Retention. Account, input, and payment data stay for as long as the account exists. DeepSeek may keep data longer for legal obligations, legitimate business interests, or to handle policy violations. Deleted accounts cannot be reactivated.
Sharing. The policy names service providers, including analytics, communications, and search providers, and entities in DeepSeek’s corporate group that handle storage, security, and foundation model training. Search providers receive the keywords of an input. Shared chat links that are published publicly may be exposed to web crawlers.
What governments have done
Italy. On January 30, 2025, the Italian data protection authority, the Garante, ordered, with immediate effect, a limitation on the processing of Italian users’ data by Hangzhou DeepSeek Artificial Intelligence and Beijing DeepSeek Artificial Intelligence, and opened an investigation. It judged the companies’ reply to its questions entirely insufficient, and the companies had said they do not operate in Italy and that European law does not apply to them (press release; order). Check the Garante for later developments.
Texas. On January 31, 2025, the governor directed the Department of Public Safety and the Department of Information Resources to add DeepSeek and five other apps to the state’s prohibited technologies list. The list bars state employees and contractors from using them on state-owned devices and on personal devices used for work (Office of the Governor).
These are two examples. A company with government customers or regulated data should check the rules that apply to it.
Safe handling for company work
- Decide before anyone asks. Put DeepSeek on the approved or not-approved list in the AI acceptable use policy, with the owner and the review date.
- Name the data that stays out. Customer records, credentials, source code, contracts, and anything under a confidentiality or data residency obligation.
- Check the route. The app, the website, and a model hosted by another provider each have different terms. This guide covers DeepSeek’s own services.
- Block or monitor on company devices if the decision is no, and include DeepSeek in the shadow AI inventory.
- Review again when the privacy policy changes. This guide read the policy dated February 10, 2026.
Frequently asked questions
Is DeepSeek safe to use?
For company work, DeepSeek’s own privacy policy says it collects prompts, uploaded files, and chat history, stores personal data in the People’s Republic of China, and uses data to train its models. Keep company and customer data out unless the company has reviewed those terms and accepted them.
Where does DeepSeek store my data?
The privacy policy says DeepSeek directly collects, processes, and stores personal data in the People’s Republic of China. It also says data may be stored on a server outside the country where you live.
Does DeepSeek train on my chats?
Yes. The policy lists training and improving its machine learning models as a purpose for the data it collects. It lists a right to opt out of that use, and the Your Choices section describes managing or deleting chat history. The policy does not describe a setting for turning training off.
Is DeepSeek banned?
Not everywhere, but some authorities have restricted it. On January 30, 2025, Italy’s data protection authority ordered a limitation on processing Italian users’ data by the two companies behind the DeepSeek chatbot. On January 31, 2025, the governor of Texas added DeepSeek to the state’s prohibited technologies list for state employees and contractors.
Can employees use DeepSeek at work?
Only if the company has decided to allow it. Write the decision into the AI acceptable use policy, name the data that stays out, and block or monitor the app on company devices if the answer is no.
Next
Keep going
Sources
All read on 2026-10-10.
- DeepSeek Privacy Policy (last update Feb 10, 2026)
- Garante per la protezione dei dati personali, press release of January 30, 2025: the Italian Data Protection Authority blocks DeepSeek
- Garante per la protezione dei dati personali, order of January 30, 2025
- Office of the Texas Governor, Governor Abbott announces ban on Chinese AI and social media apps, January 31, 2025