DeepSeek, a Chinese AI chatbot similar to OpenAI’s ChatGPT, has rapidly become the most downloaded free app in the U.S. However, its rise comes at a time of increasing scrutiny over Chinese tech platforms, with privacy concerns prompting U.S. lawmakers to push for a TikTok ban.
Like most apps, DeepSeek requires users to agree to its privacy policy upon sign-up. Yet, most users don’t read the fine print. According to cybersecurity expert Adrianus Warmenhoven from NordVPN, DeepSeek’s privacy policy is clear: user data, including conversations and generated responses, is stored on servers in China. Given China’s cybersecurity laws, this raises alarms about government access to user information.
What Data Does DeepSeek Collect?
DeepSeek’s privacy policy outlines the vast amount of data it gathers:
1. Information You Provide
- Profile details: Name, date of birth, email, phone number, and password.
- Chat data: Conversations, prompts, feedback, uploaded files, and audio inputs.
- Customer service interactions: Proof of identity, age verification, and inquiries.
2. Automatically Collected Information
- Internet data: IP address, device identifier, and cookies.
- Technical details: Device model, operating system, keystroke patterns, system language, and diagnostic data.
- Usage behavior: Features used, browsing activity, and app interactions.
- Payment information: If transactions are made through DeepSeek.
3. Information from Third Parties
- Linked accounts: Google, Apple, and other log-in services.
- Advertisers and partners: Details on purchases and user behavior shared with DeepSeek.
What Does “Keystroke Patterns” Mean?
One of the more concerning details in DeepSeek’s policy is its collection of keystroke patterns or rhythms. While this might not be unique—TikTok collects similar data—it’s unclear how DeepSeek uses this biometric information.
TikTok has stated that this data is used to differentiate users, rather than recording specific key presses (which would be keylogging). However, privacy experts warn that biometric tracking could lead to identity theft, fraud, and surveillance risks, especially when the data is stored in China.
What Does DeepSeek Do with Your Data?
DeepSeek states that it uses user data for standard functions, including:
- Delivering personalized ads and improving user experience.
- Complying with legal obligations and security policies.
- Sharing data with its corporate affiliates and law enforcement agencies.
WIRED’s analysis revealed that DeepSeek transmits data to Baidu and Volces, two Chinese tech giants, raising concerns about data use beyond its AI functions. Additionally, user prompts may be leveraged to train new AI models.
Why Should You Be Concerned?
Ignoring data security is easy, but DeepSeek operates under China’s strict cybersecurity laws, which require companies to grant government access to user data upon request. Given the limited transparency in AI training, users cannot be certain how their personal data will be stored, analyzed, or potentially exploited.
Moreover, privacy breaches can have devastating consequences, from identity theft to unauthorized financial transactions. DeepSeek recently faced “large-scale malicious attacks,” which forced it to limit new registrations. Such incidents highlight the vulnerability of stored data.
How Can You Protect Your Data?
While privacy policies from companies like Meta, OpenAI, and Google also raise concerns, DeepSeek’s ties to China present unique risks. Experts recommend taking proactive steps:
- Read privacy terms before using AI platforms.
- Minimize data sharing by limiting permissions and disabling unnecessary tracking.
- Use secure accounts and avoid linking sensitive information.
Ultimately, safeguarding user data shouldn’t be an individual burden. Stronger global data privacy laws are necessary to protect users from potential exploitation—whether by DeepSeek, TikTok, or major U.S. tech firms.

