A padlock over the outlines of DeepSeek, Qwen, Kimi and GLM model logos, representing the data-privacy question around Chinese AI models

Chinese AI models are safe to run — the real question is where you run them, not whether the model itself is dangerous. The leading Chinese models (DeepSeek, Qwen, Kimi, GLM) are mostly open-weight software: self-host them and no data leaves your machine. The privacy and censorship risks that people worry about live almost entirely in the hosted consumer apps and Chinese cloud APIs — where, for example, DeepSeek's own policy says it stores your data in China. Understand that one distinction and the whole question becomes manageable.

Key takeaways

  • The model ≠ the risk. The weights are just math. Risk comes from the endpoint — official app, Chinese-hosted API, or self-hosted open weights.
  • DeepSeek's app/API stores data in China and trains on it by default (opt-out available), per its own privacy policy.
  • International endpoints differ. Kimi (Moonshot) and GLM (Z.AI) say their global platforms run from Singapore, not the mainland; Z.AI says its API doesn't store content.
  • Censorship is real but not uniform. A 2026 Stanford study confirms more refusals on political topics — yet some Chinese models censor far less than others, and the filtering is weakest in the raw open weights.
  • The safe path: self-host the open weights (or use a Western-hosted copy). You keep the low price and capability, and your prompts never reach a Chinese company.

The One Distinction That Answers the Whole Question

"Is DeepSeek safe?" is the wrong question, because "DeepSeek" is three different things wearing the same name. There are three ways to use almost any leading Chinese model, and they have completely different safety profiles:

1. The official consumer app or website. This is what most people mean when they ask. You type into DeepSeek's app or Kimi's website, and your prompts travel to that company's servers under that company's terms. This is where the real privacy questions live.

2. The official API, hosted in China (or Singapore). Developers calling the vendor's API are bound by the same data-location and retention terms as the app — with some vendors routing international traffic through Singapore instead of the mainland.

3. The open weights, self-hosted. DeepSeek, Qwen and GLM publish their model weights openly. You can download them and run them on your own hardware, or through a US or EU cloud provider. In this mode your data never touches a Chinese company, and most of the content filtering baked into the consumer apps simply isn't there. This is the setup serious teams actually use.

Hold on to that split. Nearly every scary headline about Chinese AI is really a statement about option 1, quietly generalized to options 2 and 3 where it doesn't apply.

Where Your Data Actually Goes, Provider by Provider

Here's what the vendors' own policies say — not speculation, the documents they publish.

DeepSeek. DeepSeek's privacy policy states directly that it "collect[s], process[es] and store[s] your Personal Data in People's Republic of China." If you use DeepSeek's app or its first-party API, your prompts and uploads are stored on servers in China. That is not a rumor; it's the first-party term of service.

Kimi (Moonshot AI). Moonshot's international Kimi platform states that it stores collected information on servers located in Singapore, not mainland China. For users outside China, that's a materially different jurisdiction — though still subject to Moonshot's own retention and training terms (see below).

GLM (Zhipu / Z.AI). Zhipu's international brand, Z.AI, says it generally provides its services from Singapore, and that for its API services specifically, user-provided and generated content is processed in real time and not stored. That's one of the more privacy-forward positions among the Chinese vendors — for the API tier.

Baidu (Ernie). Baidu AI Cloud's international terms reserve the right to store and transfer user information to the country where its (or its affiliates') facilities are located, and to move that data to affiliates in other countries at its discretion. In plain terms: less specific about where your data ends up, more discretion retained by Baidu.

The pattern is clear: the international, developer-facing endpoints (Kimi, Z.AI) have moved to Singapore and softer retention, while the flagship consumer product (DeepSeek) is explicitly China-hosted. If data location matters to you, the vendor and the tier both matter.

Do They Train on Your Conversations?

This is the second real question, and the answer varies by vendor:

  • DeepSeek says it uses your data "to train and improve our technology, such as our machine learning models," by default — but it also grants a "right to opt-out of using your Personal Data for training our models." So: on by default, off if you act.
  • Kimi (Moonshot) states it uses user input and generated content (prompts, audio, images, video, files) to optimize and train its models, and its international policy provides no clearly stated opt-out. Assume your content can be used for training.
  • Z.AI (GLM) lists model training as a purpose for processing, but says API content specifically is processed in real time and not stored — the strongest of the three positions for developers.

Notice the recurring escape hatch: none of this applies to the open weights. When you run a model like GLM on your own infrastructure, there is no vendor collecting anything to train on. The training-on-your-data question only exists because you chose a hosted service.

The Censorship Question — and Why It's Not Uniform

Chinese models do censor. This is well documented and worth being honest about. A 2026 study from Stanford's China center, published in PNAS Nexus, found that large language models originating in China show "substantially higher rates of refusal to respond, shorter responses, and inaccurate responses" to political questions than models developed outside China. Ask a Chinese model about Tiananmen, Taiwan's status, or Xinjiang and you will frequently hit a wall, a deflection, or a state-aligned framing.

But two nuances get lost in the usual telling, and both matter for a real decision.

First, censorship is not uniform across vendors. Independent testing through 2026 has found that some Chinese models filter politically sensitive content far more aggressively than others — with certain Moonshot Kimi releases approaching Western models like Claude and GPT on neutrality tests, while some DeepSeek releases censor heavily. "Chinese models censor" is true as a group average and misleading as a blanket claim about any specific model.

Second, the censorship is topic-shaped and layer-shaped. Analysts have noted that Chinese open models are comparatively permissive on, say, US political speech, and only clamp down on queries about China specifically. And because much of the filtering is applied at the hosted-service layer rather than burned irreversibly into the weights, a self-hosted or Western-hosted deployment behaves noticeably more openly than the official app. If you're using these models for coding, analysis, writing or translation — which is what the vast majority of users actually do — you will likely never touch the censored surface at all.

The honest summary: Chinese models are more censored on China-related politics, meaningfully so — but the effect is concentrated in the consumer apps, varies a lot by vendor, and is close to irrelevant for the everyday coding, writing and data tasks most people use them for.

What China's AI Rules Actually Require

The censorship isn't arbitrary corporate caution — it's regulated. China's 2023 Interim Measures for the Management of Generative AI Services, administered by the Cyberspace Administration of China (CAC), require providers to register generative AI services that can influence public opinion, display model names and filing numbers, and keep outputs aligned with state content rules. Every model released to the Chinese public passes through this filing regime.

Two practical consequences follow. One: the alignment you see in the official apps is a legal obligation for the vendor, which is exactly why it's strongest there and weakest in the self-hosted weights. Two: enforcement is real — in 2025, a Chinese public-security-affiliated body cited dozens of apps, including those from Kimi and Zhipu, for personal-data-protection violations, a reminder that these companies operate under active regulatory pressure at home.

So — Are They Safe? A Practical Verdict

Match the tool to the sensitivity of the task. That's the whole game.

Casual, non-sensitive use (brainstorming, coding help, learning, drafting). The official apps and APIs are fine. The realistic worst case is that your prompts get stored abroad and possibly used for training — an annoyance, not a catastrophe, for content you'd be comfortable posting publicly anyway. The capability-per-dollar here is genuinely excellent; Chinese open-weight models have pushed the price of frontier-grade AI down by roughly an order of magnitude, and that's a real gift to anyone on a budget.

Confidential, regulated, or business-critical data (client files, source code, personal data, anything under GDPR). Do not paste it into a Chinese-hosted consumer app. Instead, self-host the open weights or use a Western cloud deployment of them. You get the same model, the same low cost, none of the data-location exposure, and far less content filtering. For a European operator, this is also the only setup that keeps you cleanly on the right side of data-transfer rules.

If political or China-related content is core to your work (journalism, policy research, human-rights work), treat the official Chinese endpoints as unreliable narrators on those specific topics, and cross-check against a Western model. For everything else, the censorship simply won't come up.

None of this is unique to China, incidentally. Every hosted AI service — American ones included — stores prompts, has retention policies, and makes content-moderation choices you don't control. The difference with Chinese models is jurisdiction and the political dimension of the filtering. The defense is the same one that works everywhere: for anything sensitive, run the model where you control the data. With open weights, you can. Not sure which model fits your use case and risk tolerance? Our free picker narrows it down in about 30 seconds — and if the politics of all this interests you, we went deeper in Is AI Left-Wing or Right-Wing?

Frequently Asked Questions

Are Chinese AI models safe to use?

It depends on how you run them, not on the model itself. The open-weight models — DeepSeek, Qwen, Kimi, GLM — are just software; when you self-host them, no data leaves your machine and there is no meaningful privacy risk. The risk lives in the hosted services: DeepSeek's own privacy policy states it stores user data in China, while the international API endpoints for Kimi and GLM say they operate from Singapore. For casual, non-sensitive use the risk is low; for confidential or regulated data, prefer self-hosting or a Western-hosted deployment of the same open weights.

Does DeepSeek store my data in China?

Yes, if you use DeepSeek's own app or API — its official privacy policy states it collects, processes and stores personal data in the People's Republic of China, and uses it to train its models by default (with an opt-out). If you run DeepSeek's open weights yourself or through a Western host, your data never reaches DeepSeek's servers.

Do Chinese AI models train on your data?

Some do by default. DeepSeek uses user data for training with an opt-out available; Moonshot's international Kimi platform uses user content to optimize its models with no clearly stated opt-out; Zhipu's Z.AI says API content is processed in real time and not stored. Self-hosting the open weights removes the question entirely.

Do Chinese AI models censor answers?

On politically sensitive topics — especially those relating to China — yes, measurably more than Western models, per a 2026 Stanford study. But it's not uniform across vendors, and it's far weaker in the open weights than in the official consumer apps, because the filtering is largely applied at the hosted-service layer.

What is the safest way to use a Chinese AI model?

Self-host the open weights, or use a Western-hosted deployment of them. Because DeepSeek, Qwen and GLM ship as open weights, you can run them on your own hardware or through a US/EU cloud. Your prompts never reach a Chinese company, most content filtering doesn't apply, and you keep the low cost and strong capability.

Is Qwen safe for business use?

Qwen is Apache-2.0 open-weight across most of its lineup, making it one of the more business-friendly Chinese models: you can self-host it with nothing leaving your environment. If you call Alibaba's hosted Qwen API, you're subject to Alibaba Cloud's terms and data location — so route sensitive workloads through a self-hosted or Western-cloud deployment and keep the hosted API for non-confidential tasks.