
Judgment matters more than features when you're building something real.
For most of the last year or so, I couldn't go a week without seeing someone mention DeepSeek. Forums, newsletters, YouTube comments- everywhere I looked, someone was either calling it a revolution or a threat. Most of the coverage landed somewhere between breathless enthusiasm and vague alarm, and very little of it felt like it was written for someone actually trying to build something online.
I stayed quiet. Not because I didn't have an opinion, but because I didn't have an informed one yet. That distinction matters to me more than it probably should.
So I did what I usually do when something is generating more heat than light. I slowed down, read what I could find, and tried to figure out what the question actually was before I tried to answer it.
What I found wasn't complicated. But it was specific, and specific is what you deserve when you're trying to figure out whether a tool belongs in your workflow.
This is what I learned and what I think you need to know before you decide.
Let's start with what's true, because it gets buried in most of the coverage.
DeepSeek is genuinely good. The underlying model is capable, the reasoning is strong, and for a long time it was free to use at a level that made tools costing twenty dollars a month look overpriced. When it appeared on the scene in early 2025, it caught the attention of people far more technically sophisticated than either of us, and they weren't wrong to take it seriously.
The performance claims held up under scrutiny in ways that surprised many people who expected them not to.
Manus followed a similar path. It positioned itself as an autonomous agent that could carry out multi-step tasks on your behalf, and the demos were impressive enough that tens of thousands of people joined a Discord server linked to the project within days of its launch. That kind of response doesn't happen without something real behind it.
So if you've looked at these tools and thought they seemed worth trying, you weren't chasing hype. The capability is legitimate.
That's where the easy part of this conversation ends.
Here's the question most people skip.
Before you evaluate what any AI tool can do for you, it's worth spending thirty seconds thinking about what you're giving it. Every prompt you type is information. It might be a draft email to your list. It might be a product idea you've been sitting on for months. It might be details about your subscribers, your offers, your pricing, or your strategy. You type it in, the tool responds, and the exchange feels like a private conversation.
It isn't always.
When you use a hosted AI tool, meaning you're accessing it through an app or a website rather than running it on your own hardware, your prompts go somewhere. They travel to a server, get processed, and in many cases get stored. Where that server is located, and whose laws govern what happens to your data once it arrives there, is something most people never think to ask.
For casual questions on a personal device, the risk is low. If you're asking a tool to suggest a dinner recipe or explain a concept you read about, the stakes of that data leaving your hands are minimal.
But if you're building a business, the inputs look different. Your list-building strategy, your email sequences, your product concepts, your subscriber data- these aren't throwaway content.
They represent real work, real relationships, and in some cases real obligations to the people who trusted you with their information.
That's worth knowing before you type the first prompt.
DeepSeek's privacy policy doesn't hide the answer. It states it directly.
Your personal data is collected, processed, and stored in the People's Republic of China. That's not a paraphrase or an interpretation pulled from a critic's summary. It's what the policy says.
And once your data is stored inside China's legal jurisdiction, a specific piece of legislation becomes relevant: the 2017 National Intelligence Law, which requires any organization or citizen to support, assist, and cooperate with state intelligence work on request.
It doesn't have to notify the user when that happens.
This is the single fact behind every ban, every investigation, and every restriction you've seen applied to these tools. Not the model quality. Not the country of origin as a point of national pride or prejudice. Just this: data stored there is subject to laws that give a government broad, quiet access to it, with no mechanism for you to know it happened.
Italy's data protection authority moved to block the app within 72 hours of opening an investigation. Thirteen European jurisdictions launched their own inquiries. At least 17 US states followed. Australia, Taiwan, South Korea, and India all imposed restrictions within government sectors.
When that many regulators, across so many different legal systems, reach the same conclusion that quickly, it's worth paying attention to what they all read.
They all read the same privacy policy you can.
I want to be careful here, because it's easy for this conversation to slide into territory it doesn't belong in.
This isn't a political argument. I'm not making a case about trade policy, national security strategy, or the broader US-China relationship. Those are conversations for people far more qualified than me, and they're not what you need to decide your workflow.
What I will say is this. When regulators who rarely agree on anything across Europe, Asia, Australia, and the United States all arrive at the same conclusion about a specific tool, and they all point to the same clause in the same document as their reason, that's a signal worth reading.
Not as a political statement. As information.
The pattern matters too. DeepSeek wasn't the only tool in this category that raised questions. Manus, the autonomous agent that generated significant buzz earlier this year, carried similar concerns about data handling and transparency. Some of the same states that moved on DeepSeek moved on Manus as well.
The issue isn't one app from one company. It's a category of tools where the data jurisdiction question hasn't been resolved in a way that gives you clear, enforceable protection.
You don't have to follow every government ban to take something useful from the pattern. You just have to ask whether the people who read the fine print for a living are seeing something you haven't looked at yet.
Most of the time, they are.
This conversation has a nuance most coverage skips, and it's worth understanding even if you never act on it.
DeepSeek is open-source. That means the underlying model the actual code and weights that power its reasoning is publicly available. Developers can download it, run it on their own hardware, and use it without ever sending a prompt to a server in China.
When you self-host a model like this, there is no cross-border data flow. Your inputs never leave your machine. The privacy concern that drives every ban on the hosted app simply doesn't apply.
That's a real and meaningful distinction.
It's also not relevant to most people reading this.
Self-hosting an AI model requires technical knowledge, specific hardware, and a willingness to manage infrastructure that has nothing to do with building an online business.
It's a legitimate path for developers and technically sophisticated users. For someone focused on growing a list, writing content, and building trust with an audience, it's a detour that leads nowhere useful.
I mention it because understanding where the risk actually lives changes how you think about the whole category. The problem was never the model. It was always the hosted app, the convenient, free, sign-up-and-start-typing version that most people use.
That's the version where your prompts travel somewhere you can't see, under terms you may not have read, governed by laws you can't enforce.
The tool itself isn't the issue. The question is always what happens to what you put into it.
So where does this leave you?
Not with a list of banned tools or a mandate to avoid anything not built in the United States. That's not a useful framework, and it's not what I'm suggesting. Plenty of tools built by American companies have their own data practices worth reading before you hand over your business information. The principle here applies across the board.
What it leaves you with is a question to ask before anything goes into your workflow. Not "does this tool work?" That's almost always answerable with a quick search or a free trial.
The question that matters more is simpler: do you know what you're agreeing to when you use it, and do you know where what you give it actually goes?
For most established tools Claude, ChatGPT, and others built and hosted under Western legal frameworks that question has a clear enough answer for you to make an informed decision. You may not love every aspect of their data policies, but the policies are readable, the jurisdictions are known, and the legal protections are enforceable.
That's a different situation from handing your prompts to a hosted service operating under a legal framework that gives you no visibility and no recourse.
The practical answer for someone building an online business right now is to work with tools where you understand the tradeoff. Pick one or two that fit your workflow, learn them well, and don't chase every new release just because the demo looked impressive.
Capability is easy to find in 2026. Judgment about what you're actually agreeing to is rarer, and it matters more than it gets credit for.
That's the whole argument. It was never about China.
I started this piece by telling you I stayed quiet while everyone else had a take. That wasn't stubbornness. It was a habit I picked up long ago, in a job where the difference between signal and noise wasn't academic. You acted on one and ignored the other, and getting them confused had consequences.
The noise around DeepSeek was loud. The signal was one sentence in a privacy policy that most people never read.
That's the pattern I keep seeing when new AI tools hit the market. The demo lands, the coverage spikes, and somewhere in the middle of all of it, the question that actually matters gets skipped. Not because it's hard to find. Because nobody slows down long enough to ask it.
You don't have to avoid every new tool that comes along. You don't have to wait for a government ban before you form an opinion. You just have to ask one question before anything touches your business: do I understand what I'm agreeing to here?
Most of the time, the answer is a five-minute read away.
That's operating above the noise. Not louder. Not faster. Just clearer.
If my story sounds familiar, the newsletter is where I write about what I've learned from it. Above the Noise goes out every week, honest thinking about trust, attention, and building something real online. No hype, no shortcuts.
David Wakeman
Operate above the noise

© Copyright David Wakeman. All Rights Reserved