Does DeepSeek Train on API Data? A Policy Investigation
Updated 2026-09-22: rewritten. The original conclusion (keep sensitive data off the API) held up, but the reasoning had a gap â it read only the Open Platform Service Agreement and missed the training grant in the parent agreement. The three policy versions are byte-for-byte the same versions I checked in May, so the terms didnât change; the reading did. Quotes below are translated from the zh-CN originals (the controlling text for mainland accounts); all re-fetched on 2026-09-22.
The Question
I call the DeepSeek API. Do my prompts and completions get used to train their models?
The Answer
âThe Open Platform agreement says nothing about trainingâ is true â but âwonât trainâ does not follow from it.
DeepSeekâs data rules are three agreements stacked on top of each other. The training grant sits in clause 4.3 of the parent User Agreement, and clause 1.1 of that same agreement explicitly counts the API as a âServiceâ. The real state of affairs for API traffic is undisclosed: DeepSeek neither commits to not training on API inputs/outputs, nor states whether it collects or retains them at all.
| What I use | What the terms say | Can I opt out? |
|---|---|---|
| Web/App chat | â Explicitly says inputs/outputs may be used for training (de-identified) | â Turn off âć°ćŽç¨äşäźĺä˝éŞâ (Data used to optimize experience) |
| Open Platform API | â ď¸ Child agreement has no training clause, but parent clause 4.3 is not displaced; Privacy Policy never lists prompt content as collected | â No toggle in the Open Platform console |
The key point: the three agreements stack, they donât replace each other
Open Platform Service Agreement (updated 2026-04-22, effective 2026-04-29), opening paragraph:
â[It], as a specific agreement referred to under, and a constituent part of, the DeepSeek User Agreement, applies in particular to you, as an individual or enterprise developer, using the application programming interface (API) or other developer tools provided by this platformâŚâ
DeepSeek User Agreement (updated/effective 2025-09-05), preamble:
âWhen you use a particular feature of the Service, there may be a separate agreement for that feature⌠Where this Agreement conflicts with a specific agreement, the specific agreement prevails. All of the foregoing terms and rules form an inseparable part of this Agreement.â
â A child agreement overrides the parent only where they conflict on the same point. Silence is not a conflict, so clause 4.3âs training grant is not carved out for API traffic. Judging what happens to API data from one document is not enough.
Division of labour across the three:
| Document | Version | What it says about training |
|---|---|---|
| User Agreement 1.1 + 4.3 | 2025-09-05 | 1.1 defines âServiceâ to include the API; 4.3 grants use of âinputs and corresponding outputs collected by the Serviceâ for model training and service optimisation, plus a free non-exclusive licence |
| Open Platform Service Agreement | effective 2026-04-29 | No training grant; 4.2 keeps input rights with you and assigns outputs to you; 5.5 routes personal-information processing to the Privacy Policy |
| Privacy Policy | 2026-02-10 | Preamble scope expressly includes the API; §I.2 (chat) carries the training clause; §I.3 (Open Platform) lists only real-name identity, e-mail and payment records â no prompt content |
Evidence
1: The parent agreement says training happens, and its service definition includes the API
Source: DeepSeek User Agreement, clauses 1.1 and 4.3 (fetched 2026-09-22, version 2025-09-05)
1.1 âOur products and services include ⌠software development kits (SDKs) and application programming interfaces (APIs) for use by third-party websites and applicationsâŚâ
4.3 âTo provide you with a continuous, high-quality service, on the premise of secure encryption processing and strict de-identification that cannot re-identify a specific individual, we may use the inputs and corresponding outputs collected by the Service for model training and service optimisation. On that premise, you grant DeepSeek a royalty-free, non-exclusive licence⌠If you refuse to have your data used for model training, you may opt out in-product by turning off âData used to optimize experienceâ.â
2: The child agreement has no training grant â but it points personal-data handling at the Privacy Policy
Source: Open Platform Service Agreement (fetched 2026-09-22, effective 2026-04-29)
- No training authorisation anywhere in the text (the âtraining other models, e.g. distillationâ wording in 4.2 is a right granted to you, not to DeepSeek)
- 4.2 âYou retain any rights, title and interest you hold in the inputs you submit⌠We assign to you any rights, title and interest in the content of the outputs of this Service.â
- 5.5 âWe will collect and process personal information generated and provided by you, as a personal-information subject, when using the Open Platform services in accordance with the DeepSeek Privacy Policy.â
- No data-retention period, deletion mechanism, or logging terms
3: The Privacy Policy covers the API, but never mentions API prompt content
Source: DeepSeek Privacy Policy (fetched 2026-09-22, version 2026-02-10)
Preamble âUnless otherwise stated, this Privacy Policy applies to the DeepSeek web pages, applications, mini-programs, software development kits (SDKs) and application programming interfaces (APIs) for use by third-party websites and applicationsâŚâ
§I.2 Chat âOn the premise of secure encryption processing and de-identification, we may use the inputs and corresponding outputs collected by the service for training the DeepSeek model and optimising the service.â
§I.3 Open Platform: the collection list is only real-name identity data, bound e-mail address, and payment order/transaction records â closing with âThe collection and processing of the above personal information applies only to the DeepSeek Open Platform.â
â This is where the actual gap is. DeepSeek neither discloses that it collects API prompt/completion content, nor that it doesnât. Inference requires the full prompt to reach the server; receiving is not the same as retaining, and the terms never say how long anything is retained. âNot listed in the collection inventoryâ is a disclosure gap, not a guarantee that the data goes unused.
4: Retention has only a statutory floor; the API docs site carries no privacy statement at all
- Privacy Policy §V.2: âComply with laws and regulations on information retention (e.g. the Cybersecurity Law requires⌠network logs retained for no less than six months)â; after account deletion or data removal, âwe will delete or anonymise your personal informationâ
- api-docs.deepseek.com: checked 2026-09-22 â the site contains no statement about data retention, logging, whether prompts/completions are stored, or training use
- The opt-out toggle âData used to optimize experienceâ is documented (Privacy Policy §VI.2.1) at an App/Web path: avatar â Settings â Data management. There is no equivalent in the Open Platform console, and it is not stated whether an API-only account can exercise it
5: Cross-vendor comparison â an affirmative commitment is achievable, and DeepSeek hasnât made one
| Provider | Does the paid API affirmatively commit to no training? | Wording | Source |
|---|---|---|---|
| OpenAI | â | âAs of March 1, 2023, data sent to the OpenAI API is not used to train or improve OpenAI models (unless you explicitly opt in).â Abuse-monitoring logs default to 30 days | your-data |
| Anthropic | â | âBy default, we will not use your inputs or outputs from our commercial products (e.g. Claude for Work, Anthropic API âŚ) to train our models.â | privacy.claude.com |
| Google Cloud Gemini | â | âGemini doesnât use your prompts or its responses as data to train its models.â | data-governance |
| DeepSeek | â No commitment, and the parent agreement keeps the grant | See evidence 1â3 | Open Platform Service Agreement |
â The difference isnât just âDeepSeek wrote nothing while others wrote somethingâ: others wrote âwe wonâtâ, DeepSeekâs parent agreement wrote âwe mayâ.
What should I do
- Keep sensitive data off the DeepSeek API â personal data of your users, trade secrets, plaintext proprietary code. Not because it certainly trains on you, but because it never promised it wouldnât and the parent agreement reserves the right
- Donât treat âthe terms donât say soâ as a green light â that mistakes textual silence for a behavioural guarantee, and it only holds after you have checked whether a higher-level agreement does say so
- Switch providers if you need an affirmative commitment â the three above give quotable, auditable text
- Local deployment is the only certainty â DeepSeek releases model weights under the MIT License; local inference removes this entire chain of questions
- Re-check periodically â reread all three agreements quarterly, watching for a new data clause in the Open Platform agreement or prompt content finally appearing in Privacy Policy §I.3. Contacts: privacy@deepseek.com / api-service@deepseek.com
Currency
On 2026-09-22 I re-fetched all three agreements: the version numbers are identical to the original survey point (2026-05-19) â User Agreement 2025-09-05, Privacy Policy 2026-02-10, Open Platform Service Agreement effective 2026-04-29. Terms change without notice; these conclusions reflect the text as of that date.
Comments