1. What the document is: DeepSeek's consumer-facing Privacy Policy, covering data collection (including User Input/Output), training data sources, retention, and international transfer.
What this wiki found — complete, every page
Presence facts, not verdicts — each flagged term links to its definition and the exact clause on this page. Absence of a badge means the term isn't currently flagged here, not that the page is risk-free.
DeepSeek – Privacy Policy
Dataset: GenGA (Generative AI Governance Archive) — 11 AI services, 2025–present
GenGA (Generative AI Governance Archive) is this wiki’s Generative-AI dataset: raw policy snapshots captured by the Open Terms Archive
genai-euproject across 11 GenAI providers (ChatGPT, Claude.ai, DeepSeek, Google Generative AI Services, Le Chat, Llama API, Meta AI, Microsoft Copilot, Perplexity, Qwen Chat, xAI). Unlike PGAv2, GenGA has no pre-tagged risk scores — all risk scoring and keyword tagging on these pages is LLM-assigned by direct reading, spanning 2025–present.
Note: This page contains documented policy clauses. Risk assessment is qualitative and context-dependent. For analysis of patterns across platforms, see:
Source: sources/GenGA/DeepSeek/Privacy Policy/ (raw Markdown captures, Open Terms Archive genai-eu dataset — no pre-tagged JSONL exists for this source)
Last updated: 2026-02-10
Note on methodology: No pre-computed
risk_score/keywordfields exist for this source. Keyword tags and clause analysis on this page are LLM-assigned, using the same rubric/vocabulary as the PGAv2 pages plus new GenAI-specific tags (input license,gdpr). Treat as first-pass analysis, not externally verified ground truth. This wiki’s risk-scoring system was retired project-wide on 2026-06-21 (seemethodology.md§4) — no page, GenGA included, computes or displays a numeric risk score.
Overview
1. What the document is: DeepSeek’s consumer-facing Privacy Policy, covering data collection (including User Input/Output), training data sources, retention, and international transfer.
2. Input rights: DeepSeek collects “text input, voice input, prompt, uploaded files, photos, feedback, chat history, or other content” as Input, and generates Output in response. It uses Personal Data — including, by implication, Input and Output — “to improve and develop the Services and to train and improve our technology, such as our machine learning models and algorithms.” A user right added 2025-12-23 lets users “opt-out of using your Personal Data for training our models or optimizing our technologies” — the same default-opt-out pattern as OpenAI’s and Anthropic’s consumer policies. DeepSeek also separately discloses obtaining “publicly available Personal Data via online sources to train our models.”
3. Output restrictions: Not addressed directly, but the document discloses a notable risk specific to DeepSeek’s “share via unique URL” feature: shared Dialogues “published on public networks, may be at risk of being obtained by third parties through technical means such as web crawlers” — DeepSeek itself warning users that their own shared conversations are scrapable.
4. Non-explicit predatory clauses: The “improve and develop the Services” training use relies on “legitimate interests” — a GDPR legal basis that lets a company process data without asking for consent, as long as its interest doesn’t override the user’s rights — as its primary justification (matching OpenAI’s and Anthropic’s pattern), with consent used only as a secondary basis for specific services.
5. Regulatory references: GDPR explicitly invoked via a third-party compliance representative: the page displays “GDPR Certification: Art 27 representation by Prighter” and “UK-GDPR Certification: Art 27 representation by Prighter” badges — Article 27 GDPR requires non-EU controllers to designate an EU representative, and DeepSeek uses a third-party service (Prighter) for this rather than an in-house EU entity (contrast with OpenAI’s/Anthropic’s own Irish subsidiaries). No EU AI Act reference found.
6. Regional variation: Significant data-residency disclosure: “we directly collect, process and store your Personal Data in People’s Republic of China” — meaning EU users’ data (this being the genai-eu dataset capture) is processed and stored in China, a materially different data-residency posture than OpenAI’s/Anthropic’s EU-entity-routing approach.
7. Key risk to users: The China-based data storage/processing for EU users, combined with using a third-party GDPR Article 27 representative rather than an in-house EU entity, is the most distinctive risk factor for this provider relative to the others in this dataset — it shifts the practical data-protection posture even though the policy itself uses familiar opt-out training and legitimate-interests language.
Flagged Keywords & Risks (LLM-assigned)
input license,train AI/models— DeepSeek uses Personal Data, including a user’s Input and Output, to train and improve its models, though users can opt out; separately, it also collects publicly available data from the web to train its models. Why it matters: the same default opt-out pattern as OpenAI and Anthropic, but here it’s combined with China-based storage of EU users’ data.gdpr— DeepSeek meets its GDPR/UK-GDPR Article 27 requirement — the rule that non-EU companies must name an EU representative — through a third-party service (Prighter), rather than its own EU entity. Why it matters: a structurally different compliance setup than OpenAI’s and Anthropic’s in-house Irish subsidiaries — worth flagging for the cross-provider regulatory comparison.
Regulatory & Research Context
Davidson et al. (2026), who directly studied DeepSeek’s policies, document jurisdictional clauses that “override their legal jurisdictions regardless of user location”; the China-based data storage disclosed here (“we directly collect, process and store your Personal Data in People’s Republic of China”) for EU users is a concrete instance of that jurisdictional gray area, made more notable by DeepSeek routing its GDPR Article 27 representation through a third-party service (Prighter) rather than an in-house EU entity. Pandit et al. (2026), who also coded DeepSeek’s terms directly, report that “all terms mentioned that inputs and outputs would also be used for other purposes beyond” the immediate service — consistent with this page’s disclosure that Personal Data, including Input/Output, trains DeepSeek’s models by default subject to opt-out.
Changes Summary
| Date | What changed |
|---|---|
| 2025-11-11 | Baseline version (“Last Update: July 4, 2025”). |
| 2025-12-23 | Several genuine additions: User Input expanded to include “voice input” and “photos” (with a new commitment not to extract biometric/voiceprint/facial-recognition data from them); a new explicit opt-out-of-training right added to the user-rights list; a new disclosure about the public-URL Dialogue-sharing feature’s web-crawler exposure risk; minor wording tweaks elsewhere (bolding, “prepayment” → “open platform” framing for payment data). |
| 2026-02-10 | Further additions: Location Personal Data collection expanded to cover location-based query responses (e.g., weather/local-recommendations), with a new commitment not to obtain precise geolocation without consent; “foundation model training and optimization” added explicitly to the list of functions performed by corporate-group data-processing entities; minor due-process/legal-compliance wording added to several clauses; duplicate China-data-storage paragraph appears twice in this version (likely a source document structuring artifact, not a substantive duplication of obligations). |
Version History
2025-11-11
- Explicit AI clause: YES
- Non-explicit predatory: NO
- Flagged keywords:
input license,train AI/models
Clause: input license, train AI/models
User Input. When you use our Services, we may collect your text input, prompt, uploaded files, feedback, chat history, or other content that you provide to our model and Services (“Prompts” or “Inputs”). We generate responses (“Outputs”) based on your Inputs.
(Note: GDPR badges and the explicit training opt-out right are not yet present in this baseline capture — see 2025-12-23 and 2026-02-10 below.)
2025-12-23
- Explicit AI clause: YES
- Non-explicit predatory: NO
- Flagged keywords:
input license,train AI/models
Clause: input license, train AI/models (wording updated — voice/photo inputs added, with a biometric-non-extraction commitment)
User Input. When you use our Services, we may collect your text input, voice input, prompt, uploaded files, photos, feedback, chat history, or other content that you provide to our model and Services (“Prompts” or “Inputs”). We generate responses (“Outputs”) based on your Inputs. Specifically, we will not extract or mine voiceprint or facial recognition information or other unique biological patterns or characteristics used to identify a specific individual from the voice inputs or photos you provided to us.
Clause: train AI/models (opt-out right, new)
the right to opt-out of using your Personal Data for training our models or optimizing our technologies.
2026-02-10
- Explicit AI clause: YES
- Non-explicit predatory: NO
- Flagged keywords:
input license,train AI/models,gdpr
input license/train AI/models (opt-out right) unchanged from 2025-12-23.
Clause: train AI/models (new explicit disclosure)
Public Personal Data. We may obtain publicly available Personal Data via online sources to train our models and provide Services.
Clause: gdpr (new — GDPR/UK-GDPR Article 27 representation badges)
GDPR Certification: Art 27 representation by Prighter […] UK-GDPR Certification: Art 27 representation by Prighter […] powered by Prighter - GDPR Compliance / Privacy Representation for EU, Switzerland, UK and Turkey.