aiwut?AI tools, decoded

Chatbot

wut is DeepSeek?

A very good AI chatbot that is free, fast, and Chinese-owned.

Wut’s the catch

Not the model — the app. DeepSeek's own privacy policy states plainly that it collects, processes and stores your personal data in the People's Republic of China, and that training on your data is the default you must opt out of. Italy's data protection authority blocked it outright in January 2025. But there is a real escape hatch almost nobody mentions: the model weights are open, so running DeepSeek somewhere else removes the entire problem.

How it scores

Transparency
Can you find out what it costs, who owns it, and how it works — before you pay?
Privacy
What happens to what you feed it, and who else gets to see it.
Value
Does the thing it charges for actually work well enough to be worth the money?
Staying power
Will this still exist, and still be the same product, in two years?

Wut it actually is

DeepSeek is a chat assistant from Hangzhou DeepSeek Artificial Intelligence Co., Ltd. It became the most-downloaded free app in the US App Store in early 2025 largely because it matched much more expensive Western models at a fraction of the cost.

It is worth being clear that the product is good. The criticism below is not that DeepSeek is a cheap knockoff — it is that the thing you are agreeing to when you use the official app is different from what you are agreeing to with a US-hosted competitor, and most people never read far enough to find that out.

Wut its own privacy policy says

This is unusually easy to check, because DeepSeek does not hide it. The policy, last updated 10 February 2026, states: "we directly collect, process and store your Personal Data in People's Republic of China." That is not a leak or an accusation — it is the company describing its own architecture.

What goes into that: your email or phone number and password, your text input, voice input, prompts, uploaded files and photos, plus device model, operating system, IP address, device identifiers, and logs of what you do in the app. The policy does commit that it "will not extract or mine voiceprint or facial recognition" from voice or photo input.

On training, note the direction of the default. The policy grants you "the right to opt-out of using your Personal Data for training our models or optimizing our technologies" — a right to opt out only exists where the behaviour is on to begin with. Data is shared with service providers, other entities in its corporate group, and law enforcement agencies under stated conditions.

Credit where it is due, because leaving this out would be building a case rather than describing one: the same policy states in capitals that "WE DO NOT ENGAGE IN TARGETED ADVERTISING, 'SELL' PERSONAL DATA OR USE PERSONAL DATA FOR 'PROFILING'". That is a stronger commitment than a lot of Western consumer apps make — including, notably, the other two tools we have decoded so far. DeepSeek's problem is jurisdiction, not ad-tech.

The reason data location matters more here than it would for a US service is China's 2017 National Intelligence Law, which obliges Chinese organisations to support and cooperate with state intelligence work. You do not need to assume bad faith by the company to conclude that its data sits under a legal regime you cannot appeal to.

Wut the regulators did about it

Italy moved fastest. Following a complaint from the consumer organisation Altroconsumo, the Garante requested details on what data was collected, on what legal basis, and where it was stored. It judged the response inadequate and ordered an immediate block on 30 January 2025; the app was pulled from Italian app stores and a formal investigation was opened.

Other jurisdictions restricted it on government devices rather than banning it outright, and several European authorities opened their own inquiries. Government-device bans are a narrower signal than they sound — they are a risk-management decision about official data, not a finding that the app is malicious.

Treat this section as regulatory context, not a verdict. As of this writing no finding has been made that DeepSeek broke a specific law in a specific way; what exists is a block order, open investigations, and a lot of institutional caution.

The escape hatch nobody mentions

Here is the part that most "is DeepSeek safe" coverage misses entirely, and it is the single most useful thing on this page.

Everything above concerns the official app and hosted API — the route where your data travels to DeepSeek's servers. But DeepSeek publishes its model weights openly. You can run the model on your own hardware, or through a Western hosting provider, and in that configuration your prompts never reach Hangzhou at all. The data-jurisdiction problem is a property of the service, not of the model.

So "is DeepSeek safe" has two different answers depending on which DeepSeek you mean, and conflating them is how you end up either needlessly avoiding a good model or needlessly leaking your prompts. If you want the capability without the jurisdiction, take the weights and leave the app.

Wut it costs and whether it lasts

The consumer app is free and the API is priced far below Western equivalents. Unlike most things we decode, the low price is not concealing a billing trick — it reflects genuinely cheaper training and inference, which is precisely why its arrival reset the market.

Staying power is good for the model and less certain for your access to it. Open weights cannot be un-published: even if the company disappeared, the released models would remain usable. The official app is the fragile part, since it is the thing regulators can and already did switch off in a given country.

The verdict

The model is genuinely excellent and the price is real, not a trick. The catch is jurisdictional, not technical: using the official app or API means your prompts live under Chinese law, by the company's own account. If that matters for what you type, use the open weights through a host you choose. If it does not, you are getting a very good chatbot for very little.

Fine for throwaway questions, code you would happily post publicly, and anything you would not mind being read. Not fine for client work, unreleased product plans, personal medical or legal detail, or anything covered by an employer confidentiality rule — and several governments have already made that call for their own staff.

This section is our opinion. Everything stated as fact above is sourced below.

Sources

Facts last checked against these on 2026-07-28.

  1. DeepSeek privacy policy (last updated 10 Feb 2026)Storage in the PRC in its own words; legal entity Hangzhou DeepSeek Artificial Intelligence Co., Ltd.; categories collected; opt-out-from-training framing; sharing with corporate group and law enforcement.
  2. Garante (Italy) — definitive limitation on processing Italian users' dataAltroconsumo complaint, information request, responses judged inadequate, block ordered and investigation opened.
  3. Euronews — DeepSeek blocked by Italian authorities, other member states open probesBlock date of 30 Jan 2025, removal from Italian app stores, parallel European inquiries.
  4. IAPP — DeepSeek and the China data questionAnalysis of direct collection into China, the open-source distinction, and the limits of extraterritorial enforcement.