Published July 29, 2026 · Updated July 30, 2026
DeepSeek is now on Secret Chat AI — and it is the new free model for everyone. It replaces Grok Fast as the default, it is faster and cheaper to run, and it is one of the strongest models in the world at reasoning, coding and analysis.
It is also the model people are most nervous about. So let's deal with that first, because the answer is more interesting than "trust us".
DeepSeek is a trademark of its respective owner. Secret Chat AI is an independent product and is not affiliated with, endorsed by, or sponsored by DeepSeek, OpenRouter, or the inference providers that serve DeepSeek's open weights. See our Disclaimers for details.
The objection, stated honestly
DeepSeek is a Chinese company. If you type into the DeepSeek consumer app, your text goes to servers in the People's Republic of China — that is not a rumour, it is what DeepSeek's own privacy policy describes. Under Chinese cybersecurity and national-intelligence law, domestic companies can be compelled to cooperate with state authorities in ways that have no clean equivalent in US or EU law.
Institutions noticed. Italy, Australia, Taiwan, South Korea, the Czech Republic, the Netherlands and a range of US federal agencies and states have restricted the DeepSeek app on official devices. Whatever your politics, when that many independent risk assessments land in the same place, the concern is mainstream rather than fringe.
Notice what those objections are actually about: where the servers are and who operates them. Every one of them is a question of hosting and jurisdiction — and hosting is the one thing an open-weights model lets you change. Hold on to that distinction, because it is the whole article. It also has a limit, and we come back to it below: moving the hosting does not move the training.
The thing that makes DeepSeek different from every closed model
With Claude, GPT or Gemini, the model and the server are welded together. There is exactly one company on earth that can serve you Claude, and if you want Claude you accept Anthropic's servers, Anthropic's terms and Anthropic's jurisdiction along with it. "Private Claude" can only ever mean a better contract with Anthropic — never a different Anthropic.
DeepSeek publishes its weights: the actual trained parameters of the model, released openly for anyone to download and run. That one decision breaks the weld. Today roughly twenty independent inference companies serve DeepSeek commercially, most of them American, none of them DeepSeek.
So the question stops being "can I trust DeepSeek with my data?" and becomes something much easier to answer: why would I send DeepSeek my data at all? The model is DeepSeek's work. The server it runs on does not have to be.
There is a nice irony here. The open release that made people nervous — a Chinese lab handing its frontier model to the world — is exactly what makes it possible to use that model without going anywhere near Chinese infrastructure. Openness cuts both ways, and this time it cuts in the user's favour.
What we actually built
"Runs on Western servers" is easy to say and easy to quietly stop being true. So it is worth describing the mechanism rather than the marketing, because the mechanism is short.
Every DeepSeek request Secret Chat sends carries three instructions to the routing layer:
- An allowlist of providers. Not a blocklist — an explicit list of permitted providers, every one of them US-headquartered. DeepSeek's own API is not on it. Neither is any Chinese- or Singapore-operated provider. Because it is an allowlist, a provider that joins the market next month cannot silently start serving our traffic; it simply is not eligible.
- Fastest first, inside the list. The allowed providers are ordered by measured speed, and the fastest one gets your request; if it is busy or down, the next-fastest takes it. This is the part people skip: a routing service left on its defaults will reach for any provider when the preferred ones are unavailable, which would defeat the whole arrangement at precisely the worst moment, silently. Because the allowlist bounds every attempt, a fallback here can only ever mean a slightly slower US server — never a different jurisdiction. If none of them can serve the request, it fails and says so.
- No-logging endpoints only. On top of the geography, each request requires an endpoint whose declared data policy is that it does not collect user data. The routing layer itself states that prompts are not retained unless prompt logging is enabled on the account — it is not enabled on ours.
All three are enforced per request, not configured once in a dashboard and hoped about. And we check the answer on the way back: every response names the provider that produced it, and one that is not on the allowlist is logged as a failure rather than quietly passed off as normal. Your Session Privacy Report — the per-message PDF Secret Chat generates — records the policy and which provider actually served the call.
What this does not fix
Every privacy claim is worth exactly as much as the limits stated next to it, so here are ours.
It anonymizes who is asking, not what the prompt says. Secret Chat AI removes you from your queries — it does not remove the data from your messages. Your text still travels to a third-party server in the United States to be answered. Removing names, case numbers and identifying details before you send is your job, on this model as on every other.
It is a routing guarantee, not a hardware audit. We can guarantee which providers a request is allowed to reach, and we record which one served it. We cannot walk into a data centre and verify a stated policy — nobody outside those companies can. So the report says what each party declares, and never dresses a declaration up as an inspected fact.
"US-hosted" is about jurisdiction, not invulnerability. It removes the specific risk that sends people looking for a private DeepSeek in the first place. It does not make any cloud model a vault.
And the big one: open weights move the hosting, not the training. Everything above is about where the model runs. None of it changes how the model was built — and DeepSeek was trained in China, by a Chinese company, under Chinese content rules.
Those rules were applied in two places, and only one of them travels with the weights. DeepSeek's own app and API add a live filter that can cut an answer off mid-sentence and swap it for a refusal; run the model anywhere else and that filter is simply not there, which is a real difference and one you get here. But a second layer went in during training, and that layer is the weights. Independent testing — including a Wired investigation — found DeepSeek censored at both the application and the training level, which is exactly why a self-hosted or US-hosted copy still declines certain questions.
So expect it: on politically sensitive topics, especially Chinese history and politics, DeepSeek may refuse, deflect, or give a state-aligned answer. Ask it about Tiananmen Square and you will probably get a polite non-answer, even though the same model discusses comparable events elsewhere in the world without hesitating. It is uneven rather than absolute — it shifts with topic, phrasing and model version — but no routing decision touches it, because there is nothing in the request to change. The behaviour is in the weights being served to us.
Two clarifications, because both matter. That refusal is not our moderation — Secret Chat screens DeepSeek on its most permissive setting, the same one Grok gets — so when you see one on this model, it came from the model. And the fix is trivial: switch to GPT, Claude, Gemini or Grok, in the same interface and the same conversation. Use DeepSeek for what it is genuinely excellent at — reasoning, code, analysis — and use something else when the subject is Chinese politics.
What this arrangement does remove is the part that was actually keeping people away: the Chinese-server question. That one is now simply not part of the deal. The training question is a different one, and it deserves an honest answer rather than a quiet omission.
What you get in the app
DeepSeek shows up once in the model picker, as DeepSeek USA, and it is the new default. Behind that one entry are the two sizes of DeepSeek V4, and the only thing the router ever decides is how much thinking your question needs:
- Smart Agentic — the default. A fast classifier reads the conversation and picks the tier.
- Flash — V4 Flash, no reasoning pass. Quick questions, drafting, explanations, ordinary conversation.
- Pro — V4 Pro at high reasoning effort. Multi-step problems, code, math, dense technical material.
All of it is free within the daily free quota — the Pro reasoning tier included. Holding Pro back for paying accounts would have made the router's one decision meaningless for most of the people using it. The daily quota is what bounds the cost, not which tier got picked.
It is also deliberately narrower than the other smart families, and it is worth being straight about what is missing rather than letting you find out mid-conversation.
No web search. DeepSeek V4 has no native search tool — no way for the model to write its own query from the conversation, which is how search works everywhere else in the lineup. The available substitute was a generic plugin that ships your last message to a search engine verbatim, with no context. We measured it against the live API before shipping: two turns into a conversation about a company, "Who is their CEO?" returned the CEOs of five unrelated companies; after a turn about the Eiffel Tower, "How tall is it exactly?" returned height-calculator apps and the model then answered that the height was not specified. It billed us per call to actively poison the follow-up questions that make up most of a real conversation. So it is gone. If DeepSeek gains a native search tool, we will revisit — until then, use Perplexity (also free) or the Web Search mode on the other families.
No image input. V4 is text-only on input, Flash and Pro alike — no provider endpoint anywhere accepts an image for this model, so the attach button is simply off rather than failing with a confusing error. A conversation that already contains images still works if you switch to DeepSeek; the older pictures are just dropped from what it receives.
No image generation, which DeepSeek has never done — use the dedicated Image Generator, or switch to GPT, Gemini or Grok for pictures.
One more difference worth knowing. For some models Secret Chat sends the provider an explicit deletion request after the fact and records the outcome in your Session Privacy Report. There is none for DeepSeek, and the report says so in plain words: per-request deletion is not needed, because routing is restricted to providers that declare they do not store prompts. Nothing was written down, and the routing layer offers no per-response deletion API anyway — so a "Deleted ✓" would be theatre.
Everything else works the way the rest of the lineup does: email-only registration, chats stored in your own browser rather than on our servers, no profile built around you, and no chat ever associated with you.
Why this replaced Grok Fast
Grok Fast did one job: be the quick, free, non-reasoning model for everyday questions. DeepSeek does that job better on every axis that matters to a user — it is faster, noticeably stronger at reasoning and code, handles far longer conversations, and costs a fraction as much to run, which is precisely why it can be genuinely free rather than a token allowance.
The full Grok family is unchanged and still there. What went away is the cut-down free tier that DeepSeek now does better.
The short version
An open-weights model is the only kind where "somewhere else" is even an option. DeepSeek published its weights; we took the option. The model is DeepSeek's, the servers are American and picked fastest-first, the endpoints declare they store nothing, the allowlist bounds every attempt so no fallback can quietly undo it — and, as with every model on Secret Chat, the request arrives with no name, no account and no IP of yours attached. What it is not is a different model: the training came with the weights, so keep another model a click away for the topics DeepSeek will not discuss.
You can read the full detail on the Private DeepSeek page, or compare it against the rest of the lineup on private AI models.
Frequently Asked Questions
- Does my data go to China when I use DeepSeek on Secret Chat?
No. Every request carries an allowlist of US-headquartered inference providers, and DeepSeek's own API is not on it. The list bounds every attempt: if the fastest allowed provider is unavailable the next-fastest one takes over, never a provider from outside the list, and if none of them can serve the request it fails with an error. We also verify which provider answered and treat anything off the list as a failure.
- How can DeepSeek run outside China at all?
DeepSeek publishes its model weights openly, so independent companies can run the model on their own hardware — around twenty do. The model is DeepSeek's work; the server it runs on does not have to be.
- Is this the real DeepSeek or a smaller copy?
It is the real DeepSeek V4, running from DeepSeek's own published weights on US hardware. It is not a distilled or shrunken variant.
- Is DeepSeek free on Secret Chat?
Yes, all of it. DeepSeek USA is the default model and every mode is free within the daily free quota — Smart Agentic, Flash and the Pro reasoning tier alike. No tier of it is held back for paying accounts.
- Can DeepSeek search the web or read my images?
No to both. DeepSeek V4 has no native web-search tool, and the generic plugin alternative sends only your last message to a search engine with no conversation context, which breaks follow-up questions — so we removed it. The model is also text-only on input, so images cannot be attached. Use Perplexity, GPT, Claude, Gemini or Grok when you need search or vision.
- Why does my Session Privacy Report show no deletion for DeepSeek?
Because there is nothing to delete and no mechanism to delete it with: the allowed providers declare they do not collect user data at all, and the routing layer offers no per-response deletion API. The report states that per-request deletion is not needed because routing is restricted to providers that declare they do not store prompts.
- What happened to Grok Fast?
DeepSeek USA replaced it as the free everyday model — it is faster, stronger at reasoning and code, and handles much longer conversations. The full Grok family is unchanged and still available.
- Is DeepSeek still censored if it runs on US servers?
Partly. DeepSeek's own app and API add a live filter that can cut an answer off mid-sentence, and running the model elsewhere leaves that filter behind. But a second layer was applied during training and is part of the weights themselves, so a US-hosted copy may still refuse or give a state-aligned answer on politically sensitive topics, especially Chinese history and politics. Hosting changes where the model runs, not how it was trained. The refusal is not our moderation — we screen DeepSeek on our most permissive setting — and you can switch to GPT, Claude, Gemini or Grok in the same conversation.
- Does this make DeepSeek safe for confidential material?
It removes the specific risk people worry about — Chinese-operated servers — and it decouples the request from your identity. But your text still reaches a third-party US server to be answered, so remove personal or confidential details before sending and verify anything important.