Deepseek app on phone and cmoputer

(Photo by Below the Sky on Shutterstock)

The Chinese artificial intelligence (AI) company DeepSeek has rattled the tech industry with the release of free, cheaply made AI models that compete with the best US products such as ChatGPT.

Users are rushing to check out the new chatbot, sending DeepSeek’s AI Assistant to the top of the iPhone and Android app charts in many countries.

However, authorities have sounded a note of caution. U.S. officials are examining the app’s “national security implications.” Australia’s former cybersecurity minister said national security agencies will soon issue formal guidance for users.

Why are governments and security experts so concerned? The main issue is the app is made in China and stores data there – but that doesn’t mean all the worry is just xenophobia.

What information does DeepSeek record?

DeepSeek does not appear to be spyware, in the sense it doesn’t seem to be collecting data without your consent. However, like many online services, it clearly tells you it will record a lot of data about you and your behavior.

Specifically, the company’s privacy policy says it collects three categories of information.

First, there is information you provide directly, such as your name and email address and any text you type in or files you upload.

Next, there is automatically collected information, such as what kind of device you are using, your IP address, details of how you use the services, cookies, and payment information.

Finally, there is information from other sources, such as Apple or Google login services, or third-party advertising and analytics companies.

This is broadly similar to the data collected by ChatGPT and Claude.

DeepSeek app on smartphone
Experts suggest avoiding DeepSeek due to potential privacy and cybersecurity risks. (Photo by Poetra.RH on Shutterstock)

What does DeepSeek do with the information?

DeepSeek says it uses this information for a range of purposes: to provide services, enforce terms of use, communicate with users, and review and improve performance.

The policy also contains a rather sweeping clause saying the company may use the information to “comply with our legal obligations, or as necessary to perform tasks in the public interest, or to protect the vital interests of our users and other people.”

DeepSeek also says it may share this information with third parties, including advertising and analytics companies as well as “law enforcement agencies, public authorities, copyright holders, or other third parties.”

DeepSeek will also keep the information “for as long as necessary” for a broad range of purposes. Again, this is all fairly standard practice for modern online services.

Causes for concern

Much of the cause for concern around DeepSeek comes from the fact the company is based in China, vulnerable to Chinese cyber criminals and subject to Chinese law.

DeepSeek stores the information it collects “in secure servers located in the People’s Republic of China.” The company says it maintains “commercially reasonable technical, administrative, and physical security measures” to protect the information.

However, we should keep in mind that China is one of the most cyber crime-prone countries in the world – ranking third behind Russia and Ukraine in a 2024 study.

So even if DeepSeek does not intentionally disclose information, there is still a considerable risk it will be accessed by nefarious actors.

China is home to a sophisticated ecosystem of cybercrime organizations that often build detailed profiles of potential targets. Microsoft and others have accused the Chinese government of collaborating with cybercrime networks on cybercrime attacks.

These organizations can use personal information to craft convincing targeted phishing attacks, which try to trick people into revealing more sensitive information such as bank details.

Should you download DeepSeek?

So, should you download DeepSeek?

If you are an experienced user who is familiar with online privacy and the capabilities of modern AI systems, go ahead – but proceed with caution and be very wary about what information you share.

And if you’re less experienced – if you’re a casual user who is less internet-savvy – my expert advice is to stay well away. DeepSeek won’t give you much you can’t get from other chatbots such as ChatGPT or Claude, and it might make your data vulnerable to Chinese cyber criminals and subject to Chinese law.

DeepSeek also raises questions for governments. Efforts to prevent scams and cybercrime often focus on banks, telecommunications companies, and social media platforms – but what about chatbots?

Mohiuddin Ahmed, Senior Lecturer of Computing and Security, Edith Cowan University

This article is republished from The Conversation under a Creative Commons license. Read the original article.

The Conversation

About The Conversation

The Conversation is a nonprofit news organization dedicated to unlocking the knowledge of academic experts for the public. The Conversation's team of 21 editors works with researchers to help them explain their work clearly and without jargon.

Our Editorial Process

StudyFinds publishes digestible, agenda-free, transparent research summaries that are intended to inform the reader as well as stir civil, educated debate. We do not agree nor disagree with any of the studies we post, rather, we encourage our readers to debate the veracity of the findings themselves. All articles published on StudyFinds are vetted by our editors prior to publication and include links back to the source or corresponding journal article, if possible.

Our Editorial Team

Steve Fink

Editor-in-Chief

John Anderer

Associate Editor

Leave a Comment

2 Comments

  1. dr. reed says:

    sure sounds like a scam like the old Stanley Pons scheme decades ago. No verification of the economics nor the validity of the method. yet the world jumps on two kids’ propaganda release. very suspicious.

  2. Douglas Nudds says:

    Nonsense anti-China propaganda. Only fools fall for it.