Is DeepSeek Safe? Privacy Risks and How to Use It Privately
DeepSeek is one of the most powerful open-weight AI models, but its app stores data in China and has been restricted by European regulators. What the risks are and how to use DeepSeek safely.
7 min readDeepSeek went from relatively unknown to the top of the app stores in a matter of days. Its models match leading Western ones on many benchmarks, and they are released as open weights that anyone can download and run.
It also drew warnings from regulators across Europe. Whether DeepSeek is safe depends on whether you mean the app or the model.
The DeepSeek app: where your data goes
DeepSeek's own privacy policy says it stores the information it collects, including your prompts and uploaded files, on servers in the People's Republic of China.
For European users and companies, that raises three problems. Chinese law gives authorities broad powers to request data from domestic companies, and EU users have little practical recourse. Transfers of personal data to a third country require appropriate safeguards under the GDPR, and regulators found them lacking. And in January 2025, security researchers at Wiz found a publicly exposed DeepSeek database containing chat histories, API keys and backend details, which was closed after they reported it.
What European regulators have done
- Italy (January 2025): the Garante ordered DeepSeek blocked after finding the company's answers about data collection and storage in China insufficient. The app was removed from Italian app stores.
- Netherlands (February 2025): civil servants were told not to use DeepSeek, and the Dutch data protection authority urged citizens to be cautious.
- Germany (June 2025): Berlin's data protection commissioner declared the data transfers to China unlawful and reported the app to Apple and Google as illegal content under the Digital Services Act.
- Czech Republic (July 2025): the government banned DeepSeek services in public administration.
South Korea, Australia and several US government agencies introduced similar restrictions.
The DeepSeek model runs anywhere
DeepSeek publishes its models as open weights under a permissive licence, so the model can run on your own hardware or on infrastructure in Europe, with no connection to DeepSeek's servers in China.
When you run DeepSeek's weights on independent infrastructure, your prompts are not sent to DeepSeek the company, and Chinese data storage rules don't apply to your conversations. What happens to your data then depends on who runs the infrastructure.
Moving DeepSeek from a Chinese app to an arbitrary Western host solves the jurisdiction problem, but many hosting providers still log prompts, keep them for debugging or use them for analytics.
How to use DeepSeek privately
If you want DeepSeek's capabilities without the privacy trade-offs, look for these guarantees:
- The model runs on infrastructure that has nothing to do with DeepSeek's own app or API.
- Prompts are encrypted on your device and only decrypted where the model runs.
- The model runs in a hardware-secured enclave (confidential computing), so even the host can't see your data.
- Nothing is retained or used for training.
- Cryptographic attestation proves the enclave is genuine.
That's how DeepSeek runs on ChatLock. The model runs inside Trusted Execution Environments on confidential computing GPUs. Your prompt is encrypted in your browser, processed in isolation, and the response is encrypted back to you. DeepSeek the company never receives anything, and neither do we.
So, is DeepSeek safe?
We don't recommend the DeepSeek app or website for anything personal, confidential or work-related, especially in the EU, given the data storage in China and the regulatory actions against it.
The DeepSeek model on private infrastructure is a good option, as long as the hosting provider can prove it doesn't see or keep your data.
FAQ
Is DeepSeek banned in Europe?
There is no EU-wide ban. Italy blocked the app in January 2025, Berlin's data protection authority asked app stores to remove it, and several governments have banned it for public sector use.
Does DeepSeek send data to China?
According to its privacy policy, the official DeepSeek app and website store user data, including prompts, on servers in China. Running the open-weight model on independent infrastructure does not send data to DeepSeek.
Is DeepSeek open source?
DeepSeek publishes its model weights under a permissive licence, so anyone can download and run them. People usually call this "open weights", since the training data and full training code are not published.
Can I use DeepSeek for work?
Avoid the official app for work data. If you want to use DeepSeek models professionally, use a provider that runs them independently with end-to-end encryption, no retention and a DPA.