DeepSeek is one of the strongest AI models in the world, and one of the cheapest to run. It is also the model people are most nervous about, for a reason that has nothing to do with its quality: DeepSeek is a Chinese company, and the consumer app sends your conversations to servers in China. This page explains why that concern is legitimate, why it does not apply to how Secret Chat serves DeepSeek, and what "DeepSeek USA" in our model picker actually means.
For the broader product context — multi-model access plus local browser storage — see our main private AI chat page, or compare providers on the private AI models page.
DeepSeek is a trademark of its respective owner. Secret Chat is an independent product and is not affiliated with, endorsed by, or sponsored by DeepSeek. See our Disclaimers for details.
The thing that makes DeepSeek different: open weights
Most frontier models are locked to their maker. If you want to use Claude, the request goes to Anthropic; if you want GPT, it goes to OpenAI. There is exactly one company that can serve you that model, and you accept their terms and their servers along with it.
DeepSeek publishes its model weights — the actual trained parameters — openly. Anyone with enough hardware can download them and run the model themselves. That is why, unusually, DeepSeek is served by roughly twenty independent inference companies around the world. The model is DeepSeek's. The server it runs on does not have to be.
This single fact is what makes a private DeepSeek possible in a way that a "private" version of a closed model never quite is. You are not asking DeepSeek to promise you better handling of your data. You are simply not sending your data to DeepSeek at all.
Where the worry about DeepSeek comes from
The concern people have is real, and it is worth stating plainly rather than waving away.
- The consumer app sends data to China. DeepSeek's own privacy policy for its chat app describes storing user data on servers located in the People's Republic of China. If you type into the DeepSeek app, that is where your text goes.
- Chinese data law is different. Under China's national intelligence and cybersecurity framework, companies can be compelled to cooperate with state authorities in ways that have no direct equivalent in US or EU law, and with far less public process.
- Government bans are not paranoia. Italy, Australia, Taiwan, South Korea, the Czech Republic, the Netherlands and a range of US federal agencies and states have restricted the DeepSeek app on official devices. Whatever you think of the politics, the fact that this many institutional risk assessments reached the same conclusion tells you the concern is mainstream, not fringe.
- Consumer terms allow training. As with most consumer chatbots, what you type into the app can feed model improvement.
Every one of those objections is about where the servers are and who operates them. None of them is about the model's weights, which are public and can be inspected by anyone. That distinction is the whole point.
What "DeepSeek USA" means on Secret Chat
In the Secret Chat model picker, DeepSeek appears as DeepSeek USA. That name is not decoration. It describes an enforced routing rule, and it is worth being precise about what it does and does not cover.
Only US-headquartered providers, by allowlist
Every DeepSeek request from Secret Chat carries an explicit allowlist of the inference providers permitted to serve it. Every provider on that list is headquartered in the United States. DeepSeek's own API and every Chinese- or Singapore-operated provider are simply not on it — not blocked case by case, but never eligible in the first place. A provider added to the wider market tomorrow cannot silently start receiving our traffic, because it is not on the list.
The fastest available server on that list
Within the allowlist, providers are ordered by measured speed and the fastest one gets your request. If it is busy or down, the next-fastest takes it — always from the same list, never from outside it. That is the part that usually gets skipped: a routing service left on its defaults will happily reach for any provider when the preferred ones are unavailable, which would quietly defeat the whole arrangement at the worst possible moment. Here the list bounds every attempt, so falling back can only ever mean a slightly slower US server, never a different jurisdiction. If none of them can serve the request, it fails and tells you so rather than routing elsewhere.
We also check the answer on the way back: every response reports which provider produced it, and one that is not on the allowlist is logged as a failure rather than passed off as normal.
Only providers that declare they do not store prompts
On top of the geography, each request requires an endpoint whose declared data policy is that it does not collect user data. The routing layer itself, OpenRouter, states that prompts are not retained unless prompt logging is switched on for the account — it is not switched on for ours. Both facts are stated in your Session Privacy Report, per message, as what the parties declare rather than as something we can inspect on their hardware.
And, as with every model here: anonymized access
This is the part that applies to DeepSeek exactly as it applies to GPT or Claude. Secret Chat is an anonymizer: we build no profile of you, and no chat is ever associated with you. The email you register with is used only for account access and payment — never to link your prompts to you. Requests reach the provider under our gateway's credentials from our servers, with no name, account, or IP of yours attached. You use the model as a stranger.
The honest boundary
Being specific here matters more than sounding reassuring, so here is what this arrangement does not do.
It anonymizes who is asking — not what the prompt says. Your text still reaches a third-party server in the United States in order to be answered. Removing names, case numbers, and identifying details before you send remains your responsibility, on this model as on every other.
It is also a routing guarantee, not a hardware audit. We can guarantee which provider a request is allowed to reach, and we record which one served it. What we cannot do is inspect that provider's servers to verify its stated policy — nobody outside the company can. So the report says what each party declares, and does not dress a declaration up as a proven fact.
Finally, "US-hosted" is a statement about jurisdiction and operator, not a claim of absolute safety. It removes the specific risk that sends people looking for a private DeepSeek in the first place. It does not turn any cloud model into a vault.
Open weights move the hosting, not the training
This one deserves its own heading, because it is the limit people are most likely to bump into. Everything above is about where the model runs. None of it changes how the model was trained — and DeepSeek was trained in China, by a Chinese company, under Chinese content rules.
Those rules were applied in two different places, and only one of them travels with the weights. DeepSeek's own app and API add a live filter that can cut an answer off mid-sentence and replace it; running the model anywhere else leaves that filter behind, and it is genuinely gone here. But a second layer was applied during training, and that one is part of the weights themselves. Independent testing — including a Wired investigation — found DeepSeek censored at both the application and the training level, which is why a locally hosted copy still declines some questions.
In practice that means DeepSeek may refuse, deflect, or give a state-aligned answer on politically sensitive topics, particularly Chinese history and politics. You may well see it: ask about Tiananmen Square and you are likely to get a polite non-answer. It is uneven rather than absolute — it varies by topic, phrasing and model version, and the same model answers freely about comparable events elsewhere in the world. No routing choice we can make changes any of it, because there is nothing in the request to change; the behaviour is in the weights we are being served.
Two things worth being clear about. First, that refusal is not ours: Secret Chat screens DeepSeek on its most permissive moderation setting, the same one we use for Grok, so a refusal you see on this model came from the model. Second, the fix is simply to switch: GPT, Claude, Gemini and Grok sit in the same interface and the same conversation, and none of them was trained under those rules. Pick DeepSeek for what it is genuinely excellent at — reasoning, code, analysis — and pick another model when the subject is Chinese politics.
How DeepSeek works in the app: one entry, two tiers, three modes
DeepSeek appears once in the model picker, as DeepSeek USA, and it is the app's default model. Behind that single entry sit the two sizes of DeepSeek V4, and the only thing the router ever decides is how much thinking your question needs.
- Smart Agentic — the default. A fast classifier reads the conversation and picks the tier: a direct answer for something straightforward, step-by-step reasoning when the question earns it.
- Flash — V4 Flash, no reasoning pass. Genuinely quick: everyday questions, drafting, explanations, casual conversation.
- Pro — V4 Pro at high reasoning effort. Slower and more careful: multi-step problems, code, math, dense technical material.
That is the whole menu, and it is deliberately narrower than the other smart models on Secret Chat. GPT, Claude, Gemini and Grok also offer web search, deep research and — for most of them — image generation. DeepSeek USA offers none of those, for reasons worth stating plainly rather than glossing over.
Why there is no Web Search mode
DeepSeek V4 has no native web-search tool — no way for the model itself to decide what to look up and write its own query from the conversation, which is exactly how search works on the other families. The alternative on offer was a generic search plugin that simply sends your last message to a search engine verbatim, with no conversation context. We tested it against the live API before shipping, and it fails in the obvious way: two turns into a conversation about a company, "Who is their CEO?" comes back with the CEOs of five unrelated companies, because the search engine never saw the earlier turns. Follow-up questions are most of a real conversation, so a feature that poisons them is worse than not having the feature. If you want a grounded answer with sources, use Perplexity (also free), or the Web Search mode on GPT, Claude, Gemini or Grok. If DeepSeek gains a native search tool, we will revisit it.
Why you cannot attach an image
DeepSeek V4 is a text-only model on input — both Flash and Pro. That is not a routing restriction we added; no provider endpoint anywhere accepts an image for this model, because the model does not take one. The attach button is therefore switched off for DeepSeek USA rather than letting an upload fail with a confusing error. If a conversation that started on another model already contains images, you can still switch to DeepSeek and continue — the older pictures are simply dropped from what it receives. To have a model look at an image, use GPT, Claude, Gemini, Grok or Perplexity.
Why there is no Create Image mode
DeepSeek generates no images at all — it is not one of the model's capabilities. Use the dedicated Image Generator, or switch to GPT, Gemini or Grok for pictures.
Free for everyone — including the reasoning tier
The entire DeepSeek USA family is free, Pro included, within the daily free quota that applies to free accounts. That is a deliberate choice rather than an oversight: capping free users at the fast tier would make the router's one decision meaningless for most of the people using it, and would quietly turn "free" into "free, but only the weak half". What bounds the cost is the daily quota, not which tier the router picked.
If you run out for the day, or want the models that do search, research and images, that is what credits are for — see pricing.
Deletion works differently here — and that is the stronger position
For some models, Secret Chat sends the provider an explicit request to delete your response after the fact, and the Session Privacy Report records the outcome. There is no such request for DeepSeek, and the report says so directly.
The reason is that deletion would be answering a question that never arises. Requests are restricted to endpoints whose declared data policy is that they do not collect user data at all — there is no stored copy to ask about afterwards — and the routing layer exposes no per-response deletion API in any case. So instead of a deletion status, your report states that per-request deletion is not needed because routing is restricted to providers that declare they do not store prompts. That is a more honest line than a "Deleted ✓" for something that was never written down, and it is a stronger guarantee than deletion-after-the-fact — provided you read it, as with every other row in that report, as what the parties declare. We can guarantee which providers a request is allowed to reach, and record which one served it. Nobody outside those companies can inspect their servers.
How DeepSeek compares in practice
DeepSeek's reputation rests on a genuinely unusual position: it performs close to the frontier closed models on reasoning, coding, and structured analysis, while being far cheaper to run. That cost difference is why it can be the free model here at all — and why a free tier on DeepSeek is a real model rather than a crippled one.
Where it stands out: multi-step reasoning, code, math, and long technical documents. Where the closed models still tend to lead: the most nuanced long-form writing and the most demanding creative work. Like every model, treat its output as a strong draft to review, not a verified answer.
Secret Chat as a private DeepSeek alternative
Secret Chat is a private AI chat app with multi-model access and local browser storage. Used with DeepSeek, it gives you:
- DeepSeek served only by US-headquartered providers — never DeepSeek's own API, never Chinese-operated infrastructure.
- The whole family free within a daily quota — Smart Agentic, Flash and the Pro reasoning tier alike — and set as the default model.
- Routing restricted to endpoints that declare they do not store prompts — and, within the allowlist, always the fastest server available.
- Email-only registration — no name, no phone, no social login — and no profile built from your chats.
- Local browser storage for chats (IndexedDB) and uploaded files (OPFS) — see how local browser storage keeps AI chat history private.
- A Session Privacy Report PDF for each message recording how the request was handled.
- The option to switch to GPT, Claude, Gemini or Grok in the same interface, even mid-conversation.
FAQs about Private DeepSeek
Does my data go to China when I use DeepSeek on Secret Chat? +
No. Every request carries an allowlist of US-headquartered inference providers, and DeepSeek's own API is not on it. The list bounds every attempt: if the fastest allowed provider is unavailable the next-fastest one takes over, never a provider from outside the list, and if none of them can serve the request it fails with an error. We also verify which provider answered and treat anything off the list as a failure.
How can DeepSeek run outside China at all? +
DeepSeek publishes its model weights openly, so independent companies can run the model on their own hardware. Around twenty do. The model is DeepSeek's work; the server it runs on does not have to be DeepSeek's.
Is DeepSeek free on Secret Chat? +
Yes — the whole family is, and it is the default model. Smart Agentic, Flash and the Pro reasoning tier are all available to free users within the daily free quota; there is no tier of DeepSeek USA that is held back for paying accounts.
Are my DeepSeek prompts stored anywhere? +
Routing is restricted to endpoints whose declared data policy is that they do not collect user data, and the routing layer states that prompts are not retained unless prompt logging is enabled on the account — it is not enabled on ours. Your chat history lives in your own browser, not on our servers. What we can guarantee is which providers a request may reach and which one served it; we cannot inspect their hardware, so the Session Privacy Report reports these as declared policies.
Why does my Session Privacy Report show no deletion for DeepSeek? +
Because there is nothing to delete and no mechanism to delete it with. The allowed providers declare that they do not collect user data at all, and the routing layer offers no per-response deletion API. Rather than print a deletion status that would be meaningless, the report states that per-request deletion is not needed because routing is restricted to providers that declare they do not store prompts.
Can DeepSeek search the web or look at my images? +
No to both. DeepSeek V4 has no native web-search tool, and the generic plugin alternative sends only your last message to a search engine with no conversation context, which breaks every follow-up question — so we do not use it. The model is also text-only on input, so images cannot be attached. Use Perplexity, GPT, Claude, Gemini or Grok when you need search or vision; DeepSeek USA gives you Smart Agentic, Flash and Pro.
Is this the real DeepSeek or a smaller copy? +
It is the real DeepSeek V4 model, running from DeepSeek's own published weights on US hardware. It is not a distilled or shrunken variant.
Does using DeepSeek here make it safe for confidential material? +
It removes the specific risk people worry about — Chinese-operated servers — and it decouples the request from your identity. But your text still reaches a third-party US server to be answered, so remove personal or confidential details before sending and verify anything important.
Is DeepSeek still censored if it runs on US servers? +
Partly, yes — and it is worth knowing before you rely on it. DeepSeek's own app and API add a live filter that can cut an answer off mid-sentence; running the model elsewhere leaves that filter behind. But a second layer was applied during training and is part of the weights themselves, so a US-hosted copy may still refuse or give a state-aligned answer on politically sensitive topics, especially Chinese history and politics. Hosting changes where the model runs, not how it was trained. That refusal is not our moderation — we screen DeepSeek on our most permissive setting — and the fix is to switch to GPT, Claude, Gemini or Grok in the same conversation.