DeepSeek’s privacy policy, last updated 2026-02-10 when reviewed, says the service may collect account information, prompts, uploads, chat history, device and network data, logs and approximate location. It states that personal data is directly collected, processed and stored in the People’s Republic of China.

What the policy covers

The policy applies to DeepSeek apps, websites, software and related services that link to it. It identifies Hangzhou DeepSeek Artificial Intelligence Co., Ltd. as controller for those services.

It does not automatically cover a downstream app built by another developer using the DeepSeek API. That developer must provide its own privacy information. Always identify the application operator, not only the underlying model.

Data users provide

DeepSeek lists account details such as email, phone, username, date of birth where applicable and password. User input can include text, voice, prompts, uploaded files, photos, feedback and chat history. Contacting support can add identity or inquiry data.

The policy says the service is not designed or intended for sensitive personal data, including health, genetic, biometric, precise-location, children’s and certain identity information. It tells users not to provide such data.

Automatically collected data

The policy describes device model, operating system, IP address, identifiers, language, crash and performance logs, feature use and actions. It may infer approximate location from IP for security and local answers. Cookies can support service operation and measurement.

An IP-derived location is not the same as GPS, but it remains personal data in many contexts. Mobile permissions and operating-system settings add another layer; grant only what a feature needs.

How DeepSeek says it uses data

Stated purposes include providing and maintaining services, enforcing terms, improving and training technology, communicating with users, preventing abuse and complying with legal obligations. The policy also describes service providers, corporate-group processing and limited third-party disclosures.

For search, it says input keywords may be shared with third-party APIs. That matters when a prompt contains a name or private project term. Use generic search queries where possible.

Data location and international transfer

DeepSeek says personal data may be stored outside the user’s country and that it directly collects, processes and stores personal data in the People’s Republic of China. Jurisdiction-specific clauses describe legal bases and rights for regions such as the EEA, Switzerland and UK.

Organisations with data-residency requirements should not infer compliance from a consumer account. Obtain appropriate contractual and legal review for the exact service.

Training and model improvement

The privacy policy says DeepSeek may use interactions to improve and train technology. The terms describe an “Improve the model for everyone” control and say users can opt out of certain processing. The live location and effect of that control should be checked in account settings.

An opt-out can reduce one use of data but does not necessarily eliminate retention needed to provide the service, secure it or comply with law. Read the full policy rather than treating one toggle as complete privacy.

User rights and controls

Depending on location, rights may include access, correction, deletion, portability, objection and restriction. The policy provides privacy@deepseek.com for requests and says identity verification may be required.

Users can manage or delete chat history through settings where available. Account deletion is described as irreversible, and some data may be retained for legal, security or claims purposes.

The policy warns that dialogues shared through a unique URL can be obtained by third parties if posted publicly, including through crawlers. Review the full conversation before sharing. Remove names, credentials, proprietary text and metadata.

Revoking a link may not remove copies already indexed or saved. Treat a public share as publication.

What not to submit

Avoid passwords, API keys, private keys, payment-card data, government identifiers, medical records, precise personal profiles, unreleased source code, customer lists and confidential contracts. Redact document properties and images as well as visible text.

For students, remove classmates’ names and follow school rules. For employees, follow the approved-service and data-classification policy. The safety guide adds technical controls.

API developer responsibilities

DeepSeek’s open-platform terms say downstream developers must disclose their own personal-information processing, obtain an appropriate legal basis and respond to user rights. API keys must not be exposed in client-side code.

Use data minimisation, retention limits, access controls and privacy-safe logs. Do not put an email or phone number in the API user_id; the documented field should be an opaque allowed identifier.

Local deployment

A local open-weight model can avoid sending prompts to DeepSeek’s hosted service, but the runtime, UI, retrieval database and telemetry determine the real data path. Keep endpoints local, restrict files, inspect logs and understand backups.

Local use changes who controls data; it does not remove the need for privacy governance.

How to check for policy changes

Open the official privacy policy — official external destination, record its last-updated date and compare material sections before publication. Recheck after new app features, region changes or enterprise terms.

This article’s frontmatter uses lastVerifiedAt because privacy is a volatile fact.

Review the current product boundaries in the DeepSeek Chat guide, then use the broader safety assessment for account, output and deployment risks. The local deployment guide explains why local inference changes, but does not eliminate, privacy responsibilities.

Conclusion

DeepSeek’s policy makes clear that hosted use involves more than the visible prompt. Understand data categories, location, training choices, third parties and rights before use. The safest default is to submit only information necessary for a low-risk task.

Useful next steps

Continue with related guidance

Put this page in context with Is DeepSeek Safe? Privacy and Security Guide, DeepSeek Chat Guide: Features, Access and Best Uses, Run DeepSeek on Windows, macOS and Linux, and DeepSeek for Students and Learning. These links cover the broader decision and the closest follow-up topics without repeating this article.

Common questions

Frequently asked questions

Where does DeepSeek say it stores personal data?

The policy says it directly collects, processes and stores personal data in the People’s Republic of China.

Can I opt out of model improvement?

The policy and terms describe an opt-out choice. Check the live account setting and its scope.

Does deleting a chat delete every copy?

The policy describes history controls, but retention and public shared copies can differ. Read current terms and request rights where applicable.

Does this policy cover third-party DeepSeek apps?

Not necessarily. The downstream app operator should provide its own policy.

Evidence

Sources

3 primary references
  1. DeepSeek Privacy Policy — official external destination

    DeepSeek · official legal policy · verified July 30, 2026

  2. DeepSeek Terms of Use — official external destination

    DeepSeek · official legal terms · verified July 30, 2026

  3. DeepSeek Open Platform Terms of Service — official external destination

    DeepSeek · official legal terms · verified July 30, 2026

Continue reading