“Safe” is doing a lot of work in that question. Safe from malware, safe from your employer, safe from a government — these have different answers, and the coverage tends to collapse them into one. Here they are separately.
First, two different things share the name
DeepSeek is a Chinese AI company that publishes open-weight models and also runs a hosted app and API. The distinction matters more than anything else on this page:
- •The models can be downloaded and run on your own hardware. A model running locally sends nothing anywhere. Whatever you think of the company, weights on your own disk cannot phone home — and this is checkable rather than a matter of trust.
- •The app and API send your conversation to DeepSeek’s servers, where it is stored under their policy and their jurisdiction. This is the part every privacy story is about.
Most people asking this question mean the app on their phone. The rest of this is about that.
Is it malware?
There is no public evidence that it is, and the app is distributed through the official stores, which apply their own review. Treating it as a virus is the wrong frame, and it distracts from the real issue — which is not that the app does something hidden, but what it openly does with what you type.
Where the conversations go
DeepSeek’s own privacy policy has described storing user data on servers located in China. That is not a leak or an allegation; it is the stated arrangement, and it is the fact everything else follows from. Data held in a jurisdiction is subject to that jurisdiction’s law, including its provisions for state access, and a user abroad has no practical route to contest a request they will never hear about.
On that basis a number of governments restricted the app on official devices, and several data protection authorities opened enquiries into its data handling. Read those actions for what they were: decisions about government devices and unresolved regulatory questions, not a finding that the app attacks its users. Check the current position with your own regulator if it matters to you — this area moves.
The question is not whether the app is hiding something. It is what happens to what it openly keeps.
The part that is not specific to DeepSeek
Nearly every hosted assistant keeps your conversations, ties them to an account, and can be compelled to produce them. The differences are jurisdiction, retention, and how much the company has chosen to collect. A US assistant is subject to US legal process; a European one to European. “Somebody else’s server, under somebody else’s law” is the default arrangement of the whole category.
So the useful question is not which company to trust. It is how much any of them need to be trusted with.
A practical answer
- •For ordinary questions — recipes, code, a first draft, a translation — the exposure is small whichever app you use, and DeepSeek is not a special case.
- •For work material, check whether your employer has a position. Many organisations have restricted specific assistants on managed devices, and that is a policy question before it is a technical one.
- •For anything about your health, your finances, your legal position or another identifiable person, the jurisdiction question is real, and it applies to more apps than this one.
- •If you want the model without the arrangement, run the open weights locally. That option genuinely exists here, which is more than can be said for most of the assistants it is compared with.
What we do differently
Secure AI takes the third route: the identifying details never leave. Names, addresses, phone numbers, card numbers, government identifiers and account references are detected and replaced with realistic stand-ins before your message reaches any model, and your real values are restored in the reply. Whichever model answers, and wherever it runs, it answers about somebody who does not exist.
That does not make us the trustworthy one and everyone else suspect. It means less of the question rests on trust at all, which is the only version of this that survives a change of company, country or policy.
Questions
Does DeepSeek train on my conversations?
Its policy has described using user content to improve its services. Read the current version before deciding — this is the kind of clause that changes, and the answer today is not necessarily the answer when you read this.
Is it safer than ChatGPT?
Different, not simply safer or worse. Both are hosted assistants that retain conversations against an account. The meaningful differences are which government can compel access, what is retained and for how long, and whether your inputs train the model. DeepSeek additionally publishes weights you can run yourself, which is a genuine advantage if you use it.
I already used it. What should I do?
Nothing dramatic. Look back at what you actually typed. If it was ordinary, it was ordinary. If it included something identifying, delete the conversation and the account if the app allows it, and treat the disclosure as having happened — because deletion is a request to the holder, not a guarantee about copies.

Try Secure AI free
Frontier AI chat — encrypted by default, with your identity stripped before any request reaches the provider.
