← AI Assistants
F

DeepSeek

Fail
DeepSeek · 🇨🇳 China
PolicyApp PermissionsNetwork TrafficFirmwareRegulatory
Technical details
Manufacturer: DeepSeek (High-Flyer Capital)

⚠️ The bottom line

DeepSeek stores your prompts on servers in China. The company says so in its privacy policy. China's National Intelligence Law requires every Chinese company to cooperate with state intelligence. Italy blocked it. Australia banned it from government devices. Taiwan banned it. South Korea banned it. The US Navy prohibited its use. DeepSeek is owned by a Chinese hedge fund. Your conversations, your questions, your code, your business queries — stored on Chinese servers, held by a company that cannot legally refuse a request from Chinese intelligence. The privacy policy doesn't hide this. It states it plainly. DeepSeek left a database open on the internet. No password. No authentication. Over a million lines of chat history, API keys, and backend logs — accessible to anyone who looked. Wiz found it. Then Cisco tested the model's safety: 100% failure rate. Every harmful prompt they tried worked. Bioweapons instructions. Malware generation. Social engineering scripts. Zero blocked. A Chinese AI company that left your conversations in an open database and built a model that says yes to everything. The "open" in open-weights apparently applied to the user data too.

Legal jurisdiction
🇨🇳 China (headquarters)
National Intelligence Law read more →
Company must secretly hand data to Chinese intelligence on request
Data Security Law read more →
State can classify any data as 'important' and demand access for national security
Spying
3/4 HIGH
Is someone spying on me?
Data Sharing
3/4 HIGH
Who gets my data?
Security
3/4 HIGH
Is it actually secure?
Honesty
2/4 MODERATE
Can I trust what they say?
CONFIGURE High-risk areas that can be partially mitigated with settings changes.
4Contradictions
3Critical
1High
0Medium
4Sources
Findings by concern
Spying 3/4 HIGH 2 findings
⚠️ criticalpolicy claim vs regulatory finding
DeepSeek stores your prompts on servers in China. The company says so in its privacy policy. China's National Intelligence Law requires every Chinese company to cooperate with state intelligence. Italy blocked it. Australia banned it from government devices. Taiwan banned it. South Korea banned it. The US Navy prohibited its use. DeepSeek is owned by a Chinese hedge fund. Your conversations, your questions, your code, your business queries — stored on Chinese servers, held by a company that cannot legally refuse a request from Chinese intelligence. The privacy policy doesn't hide this. It states it plainly.

What they claim: DeepSeek's privacy policy states it collects user data including prompts, device information, and keystroke patterns.

What we found: DeepSeek is headquartered in Hangzhou, China and is a subsidiary of High-Flyer Capital Management, a Chinese quantitative hedge fund. China's National Intelligence Law (2017) requires all Chinese organisations to "support, assist, and cooperate with national intelligence work." DeepSeek's privacy policy explicitly states data is stored on servers in the People's Republic of China. In January 2025, Italy's data protection authority blocked DeepSeek for GDPR violations. Australia, Taiwan, and South Korea banned DeepSeek from government devices. The US Navy issued guidance prohibiting its use. Your prompts are stored on Chinese servers by a company legally required to hand them to Chinese intelligence on request.

⚡ highpolicy claim vs third party research
DeepSeek collects how you type. Not just what you type — how. The rhythm of your keystrokes. The pauses between words. The speed of your fingers. Keystroke dynamics are behavioural biometrics — as unique as fingerprints. Forensic investigators use them to identify people. DeepSeek put it in the privacy policy: "keystroke patterns or rhythms." No other major AI chatbot collects this. Combined with your prompts, your IP address, and Chinese server storage, DeepSeek can identify you by the way your fingers hit the keyboard — even if you never create an account.

What they claim: DeepSeek's privacy policy states it collects "keystroke patterns or rhythms" from users.

What we found: DeepSeek's privacy policy explicitly lists keystroke patterns as collected data — a form of behavioural biometrics that can uniquely identify individuals. Keystroke dynamics are used in forensics and authentication because typing patterns are as unique as fingerprints. Combined with prompt content, device information, IP addresses, and the Chinese jurisdiction, DeepSeek collects enough data to identify, profile, and track individual users across sessions even without traditional account credentials. No other major AI chatbot explicitly states it collects keystroke biometrics.

Security 3/4 HIGH 2 findings
⚠️ criticalmarketing claim vs third party research
DeepSeek left a database open on the internet. No password. No authentication. Over a million lines of chat history, API keys, and backend logs — accessible to anyone who looked. Wiz found it. Then Cisco tested the model's safety: 100% failure rate. Every harmful prompt they tried worked. Bioweapons instructions. Malware generation. Social engineering scripts. Zero blocked. A Chinese AI company that left your conversations in an open database and built a model that says yes to everything. The "open" in open-weights apparently applied to the user data too.

What they claim: DeepSeek positions itself as an open, capable AI assistant comparable to Western frontier models.

What we found: Security researchers from Wiz discovered that DeepSeek left a ClickHouse database publicly exposed with no authentication, containing over a million lines of chat history, API keys, backend metadata, and operational logs. The database was accessible to anyone on the internet. Researchers at Cisco and the University of Pennsylvania tested DeepSeek R1 and found it failed to block a single harmful prompt across their test suite — a 100% failure rate on safety benchmarks. DeepSeek's model was jailbroken to generate instructions for bioweapons, malware, and social engineering attacks. Open-weights, open-database, open-to-everyone.

⚠️ criticalmarketing vs third party research
1 million chat logs in plaintext. Publicly accessible. API keys exposed. The iOS app didn't encrypt transmissions. Data went to ByteDance's cloud. Italy banned it in 72 hours. The US Navy banned it. A Chinese AI company stored your conversations in a database anyone could read, transmitted them without encryption, and routed them through TikTok's parent company's servers.

What they claim: DeepSeek promotes advanced AI capabilities with competitive performance

What we found: Security researchers from Wiz discovered a publicly accessible DeepSeek database containing over 1 million log entries including plaintext chat histories, API keys, and backend system details. The iOS app transmitted device information without encryption. Hard-coded encryption keys were found. Data was also transmitted to Volcengine — ByteDance's cloud platform. Italy banned DeepSeek within 72 hours. The US Navy, multiple US states, Australia, Taiwan, and South Korea imposed restrictions.

Sources