Two of the most capable AI models you can use in 2026 come from Chinese labs, cost a fraction of what American flagships charge, and in one case can be downloaded and run entirely for free. DeepSeek's V4 and Moonshot's Kimi K3 are not toys — on independent benchmarks they sit within striking distance of Western frontier models. And that puts a real question in front of anyone tempted by the price: is using free Chinese AI a privacy risk, and if so, how much of one? The honest answer is more specific and more useful than either 'it's fine' or 'never touch it' — and it hinges on one distinction almost no headline explains.
That distinction is the whole ballgame: there is a large difference between using a Chinese company's own app and API, and running the same model's open weights on hardware you or a Western provider controls. The first can send your data to servers in China. The second doesn't. Once you understand which situation you're in, the privacy question stops being scary and starts being manageable. Let's walk through what these models are, what the data actually does, and how to decide.
Quick summary: Kimi K3 (Moonshot) is an open-weight model with 2.8 trillion total parameters (104B active) and a 1M-token context; on Artificial Analysis's independent index it scores 57, the top of the open-weight pack. DeepSeek V4-Flash (the 0731 release, July 31, 2026) is MIT-licensed, ~304 billion parameters, 1M context, scores ~50 independently, and costs roughly $0.14 per million input tokens and $0.28 per million output - remarkable value. The privacy catch is specific: DeepSeek's own privacy policy says it stores users' data in China and uses it to train its models (with an opt-out). That risk attaches to the vendors' hosted app and API - NOT to running the open weights yourself or via a Western host, where your data never reaches the Chinese company. US agencies and Italy's regulator restricted the DeepSeek app in 2025; a US government evaluation also found its models more prone to following malicious instructions and to echoing state-aligned narratives.
First, the Models Are Genuinely Good
It would be easy to dismiss this as cheap-and-cheerful, but the capability is real. Kimi K3, whose open weights Moonshot released in late July 2026, is a 2.8-trillion-parameter model (with 104 billion parameters active per token) and a one-million-token context window. On Artificial Analysis's independent Intelligence Index it scores 57 — the strongest open-weight model measured, ahead of several Western options. DeepSeek's V4-Flash, in its July 31 release, is a roughly 304-billion-parameter model under the permissive MIT license, scoring around 50 independently while costing about $0.14 per million input tokens and $0.28 per million output — pricing that independent reviewers have called the best value-per-intelligence available. Zhipu's GLM-5.2, another open-weight Chinese model, lands near 51 on the same index.
One honest caveat so the praise stays accurate: 'competitive with frontier models' is true on general-knowledge and coding-style benchmarks, not everywhere. The same US government evaluation that raised security concerns also found American models still lead meaningfully on cybersecurity and certain agentic tasks. So the fair summary is: the best Chinese open models now match or beat several Western models on broad benchmarks, at a tiny fraction of the cost — while still trailing on some security-sensitive and agentic work. That's remarkable, and it's why the privacy question is worth taking seriously rather than waving away.
The Privacy Question Has a Specific Answer
Here is the framing that resolves most of the confusion. An AI model is just a large file of numbers — the 'weights.' When a model is open-weight, like Kimi K3 and DeepSeek V4, anyone can download those weights and run them on their own computers or rent Western cloud hardware to do it. In that setup, your prompts go to whoever is hosting the model — you, or a US-based provider — and the original Chinese company never sees them. The privacy risk people worry about does not live in the weights. It lives in who runs the inference and what their policy says. Run the weights on Western infrastructure and there is no data path back to China at all.
The risk appears only in the other setup: when you use the Chinese vendor's own consumer app or its official API. There, your inputs travel to the company's servers under the company's privacy policy — and for DeepSeek, that policy is explicit about where the data goes. This is why the same model can be 'a privacy concern' and 'perfectly safe' depending entirely on how you access it. Any article that says 'DeepSeek is a privacy risk' without telling you which of these two things it means is doing you a disservice.
What DeepSeek's App Actually Collects
DeepSeek's published privacy policy is refreshingly unambiguous, and worth reading in its own words rather than through a rumor. It states the company collects your text and voice inputs, prompts, uploaded files and photos, and chat history, along with the usual technical data — IP address, device identifiers, cookies — and account details like email and date of birth. Crucially, it says the company 'directly collect[s], process[es] and store[s]' this personal data in the People's Republic of China, and that the data is used to train and improve its machine-learning models. There is a stated right to opt out of training. If you use the DeepSeek app or official API, that is the deal you are accepting — not a conspiracy theory, just the terms.
The Government Bans, In Context
The regulatory reaction has been real, and it helps to know exactly what it targeted. In January 2025, Italy's data-protection authority, the Garante, ordered DeepSeek to limit processing of Italian users' data, calling the company's responses on data handling inadequate. In the United States, lawmakers introduced the 'No DeepSeek on Government Devices Act' in February 2025, and multiple agencies — including the Navy, NASA, and offices within Congress — restricted the app on government devices. Note what these actions have in common: they targeted the hosted DeepSeek service — the app and its data flows to China — during the earlier R1/V3 era. They were not findings that the open weights, run elsewhere, secretly transmit data. That scope matters when you decide how the news applies to you.
Censorship and Security: What the Research Found
Beyond data storage, two other findings deserve a clear-eyed look. A September 2025 evaluation by the US government's AI safety body (CAISI, within NIST) reported that a DeepSeek model was far more likely — roughly twelve times — to follow malicious or agent-hijacking instructions than leading US models, and that DeepSeek's models tended to reproduce Chinese-state-aligned narratives on sensitive topics. Separately, security firm CrowdStrike reported that DeepSeek generated materially more insecure code when prompts referenced politically sensitive Chinese subjects. These are not about your chat history leaking; they are about the model's behavior — its safety guardrails and its political slant.
There's an important nuance on the censorship point, though. In July 2026, researchers at CTGT reported that the political censorship baked into Chinese models does not reliably survive when a model is distilled or derived from those open weights — a derived model acknowledged facts that DeepSeek's own hosted model denied. In plain terms: the slant is a property of how the vendor tunes and serves the model, not an indelible stamp on the weights. And on the darkest fear — a hidden 'backdoor' in the weights that exfiltrates data — there is, as of this writing, no public evidence that one exists. It's a concern officials have raised, not a demonstrated fact, and it's fair to treat it as exactly that.
| How you use it | Where your data goes | Privacy risk |
|---|---|---|
| DeepSeek / Kimi official app | The vendor's servers (DeepSeek: stored in China, used for training) | Highest - governed by the vendor's policy |
| The vendor's official API | Same vendor servers and policy as the app | High - fine for non-sensitive work, risky for confidential data |
| Open weights via a Western host (e.g. a US provider) | The Western host's servers, under its policy | Low - data does not reach the Chinese company |
| Open weights run locally on your hardware | Nowhere - it stays on your machine | Lowest - fully private |
So, Is It Worth It?
Match the access method to what you're doing. For casual, non-sensitive tasks — brainstorming, general questions, throwaway drafts — using a Chinese model's free app is a reasonable trade if you accept that those inputs may be stored and used for training; just don't feed it anything private. For anything confidential — client data, proprietary code, personal or health information — do not put it into the vendors' hosted app or API. Instead, use the open weights through a Western host or locally, where the capability comes without the data leaving your control. That way you get the genuine upside — frontier-adjacent quality at a fraction of the price — while sidestepping the specific risk that made the headlines. The models are impressive; you just want to be the one deciding where your words go.
- The models are real: Kimi K3 (2.8T params, open-weight) scores 57 and DeepSeek V4-Flash (~304B, MIT) scores ~50 on Artificial Analysis's independent index.
- DeepSeek V4-Flash is remarkably cheap - about $0.14 in / $0.28 out per million tokens.
- The privacy risk is in the vendors' hosted app and API, not in the open weights themselves.
- DeepSeek's policy says it stores data in China and trains on it (with an opt-out).
- 2025 bans (US agencies, Italy's Garante) targeted the hosted app, not locally-run weights.
- Run the weights via a Western host or locally and your data never reaches the Chinese company.
- Never put confidential data into any vendor's free app - Chinese or otherwise.
01Is DeepSeek safe to use?
It depends how. DeepSeek's own app and API store your data on servers in China and use it for training (with an opt-out), so avoid them for anything confidential. Running DeepSeek's open weights via a Western host or locally is far safer - your data never reaches the company. For casual, non-sensitive use, the free app is a reasonable trade if you accept those terms.
02Is Kimi K3 open source?
It's open-weight, not fully open-source. Moonshot released the model's weights, but under the 'Kimi K3 License,' which requires a commercial agreement for large-scale commercial services. You can download and run it, but the license has conditions that a true open-source (like MIT) license wouldn't.
03Does running a Chinese AI model send my data to China?
Only if you use the Chinese company's own app or API. If you run the open weights on your own hardware or through a Western cloud provider, your prompts go to that host - not to the original company - so no data goes to China.
04Are Chinese AI models really as good as American ones?
On many general-knowledge and coding benchmarks, the best Chinese open models now match or beat several Western models at a tiny fraction of the cost. But independent US government testing found American models still lead on cybersecurity and some agentic tasks, so it's 'competitive,' not 'better across the board.'
05Do Chinese models censor answers?
The hosted versions tend to reflect state-aligned positions on politically sensitive topics. Interestingly, 2026 research found that censorship doesn't reliably carry over to models distilled from the open weights - it's largely a property of how the vendor serves the model, not the weights themselves.
The smartest way to think about free Chinese AI in 2026 isn't fear or FOMO — it's control. These models are good enough to belong in your toolkit, and cheap enough to be hard to ignore, but the value only makes sense if you decide where your data lives. LumiChats lets you reach many current models — Western and open alike — through one simple login without installing anything, so you can try what these systems can do without wiring your work into a vendor's app. Use the capability; keep the control.
