AI Regulation

AI Gateway Privacy: Your Prompts Can Reach China and Train Models

AI Gateway Privacy: Your Prompts Can Reach China and Train Models

Call deepseek/deepseek-v4.1-flash on OpenRouter with the default request settings, and unless you have turned off the account switch for providers that may train, nothing stops your prompt from reaching DeepSeek’s own API in China. OpenRouter’s panel for that endpoint reads “Prompt training: Yes” and “Headquarters: CN.” In one-day counts of tokens (the text units models are billed by), the endpoint served 14.5% of the model’s traffic on September 26, 2026, and 13.2% on September 28. DeepSeek’s API terms, under mainland Chinese law, don’t commit to keeping API inputs out of training, and its model and training disclosure says training question-answer pairs are “produced by our research team, with a small portion potentially based on user input.” It says such input is de-identified and users can opt out, but not whether API traffic is included or how an API customer would opt out.

Left: OpenRouter's panel for DeepSeek's own endpoint on deepseek-v4.1-flash, September 28, 2026, showing Prompt training: Yes, a token share of 13.2% and Headquarters: CN. Right: DeepSeek's model and training disclosure, which says its question-answer training pairs are produced by its research team, with a small portion potentially based on user input.

Red boxes in the screenshots mark the lines we cite. On a gateway, a model developer such as DeepSeek publishes a model, providers such as Baidu or DeepInfra each run a copy, and each provider’s deployment is an endpoint; the gateway picks an endpoint for every request.

The gateway’s labels can’t be taken at face value either. For a sibling model, deepseek-v4-flash, OpenRouter labels Baidu, one of the cheapest providers, as not training on prompts, but the terms linked on Baidu’s listing let Baidu use your content “to develop, enhance, and improve AI services,” with no opt-out. If OpenRouter has a stricter agreement with Baidu, it isn’t public.

Training is what makes this worse than a transfer. A log can be deleted, but data that has already gone into a model can’t be pulled back out; ByteDance’s BytePlus says in its own data terms that data authorized before you opt out “cannot be technically deleted.” This article first sorts out which retention is needed, then turns to training and the other copies you never agreed to.

Key takeaways

  • Most retention in the AI middle layer is legitimate: billing, security logs, and caches or tracing you turned on. The risk lies in defaults that serve the vendor, and training is the one you can’t reverse.
  • OpenRouter routes by price and doesn’t filter on training by default. Baidu and StreamLake, which OpenRouter lists as China-headquartered, together carried 45% of one day’s deepseek-v4-flash tokens on September 26 and 38% on September 28.
  • Free models are often paid for with data. OpenRouter says “most free endpoints train on, or may publish, the prompts they receive,” and ByteDance’s Volcano Ark and BytePlus trade up to 5 million free tokens per model a day for a perpetual license to prompts and outputs.
  • Training rights follow the contract, not the model or its country. Under Zhipu’s mainland terms, prompts sent to the free GLM-4.7-Flash can improve Zhipu’s services and, once anonymized, train models; under Z.ai’s Singapore terms they can’t.
  • For US companies, sending bulk US sensitive personal data to a provider organized or headquartered in China, or at least 50% owned by such companies, can be a restricted transaction under the Justice Department’s data security rule.
  • Deploying an open-weight model (one whose weights anyone can download and run) yourself keeps the model developer out of the data path, but check the platform’s region and log defaults.

This is the fifth article in our series on privacy across the AI supply chain, after the fourth on AI agents. It covers AI gateways, model hosts, free model offers, self-deployment platforms and tracing tools, as documented between September 25 and 28, 2026.

How we did this. This analysis rests on vendors’ public docs, terms, privacy policies and source code, OpenRouter’s public API and model pages, and regulators’ published texts. We have not verified these flows with traffic capture and plan to test them separately.

Which data retention do AI gateways and hosts actually need?

Retention is necessary when the service can’t run without it, and questionable when the vendor keeps data for its own benefit by default. We sorted the purposes vendors give into four groups.

Retention purposes in the AI middle layer. Billing and usage metadata and security logs are needed, with the vendor as processor. Abuse monitoring and legal holds are allowed by law. Gateway request logs, caching and tracing are features the customer chooses. Dataset and evaluation copies, product improvement, model training, and session replay or analytics are hidden defaults; the last three make the vendor a controller.

Needed means the service can’t run without it, such as billing; Chosen means a feature the customer turns on, such as caching; Allowed means a vendor purpose the law permits, such as abuse detection or a court-ordered hold; Hidden means on by default, not needed for the service and easy to miss. The last column applies the GDPR test: Processor means the vendor processes data only for you, Controller means it uses the data for its own purposes and becomes a controller for that processing, and Depends means it varies by case.

Hidden defaults are where the risk sits. Together says “Store prompts and model responses: on by default. Stores prompts and outputs for product improvements,” while its terms say it uses content “solely as necessary to provide the Services.” Coze uses customer content “to train and improve our technology, such as our machine learning models and algorithms,” and keeps it “for as long as you have an account.” n8n Cloud records user sessions with PostHog and deletes them after 21 days, but PostHog is not on its subprocessor list, which is consistent with n8n treating the analytics as its own processing.

The same clause can pass in the US and fail in the EU. European regulators treat a vendor’s own use of your data as a controller activity: the European Data Protection Board (EDPB) says a processor “may not carry out processing for its own purpose(s),” and the UK ICO says an AI developer processing data “for their own purposes” is “a controller for that processing.” By contrast, California’s CCPA regulations let a service provider use customer data to improve its own services, within limits.

How can an AI gateway send prompts to China, and into training, without telling you?

It picks endpoints by price and shows each provider’s data policy without routing on it. OpenRouter’s docs say that by default it will “load balance requests across providers, prioritizing price.” Its data_collection parameter defaults to “allow,” which it defines as “allow providers which store user data non-transiently and may train on it,” and “OpenRouter does not have routing rules that change based on data retention policies of providers.” It also has two account-level switches, one for paid and one for free models, that allow routing to providers that may train; it doesn’t document their defaults. A zdr: true option limits routing to providers on its zero-retention list.

OpenRouter token share by provider for two DeepSeek models, one-day shares read from OpenRouter's endpoint panels on September 26, 2026. For deepseek-v4-flash: Baidu (headquartered in China) 37.7%, Alibaba (Singapore headquarters, data centers in Singapore and China) 10.1%, Relace 8.3%, StreamLake (China) 7.6%, DeepInfra (US) 4.8%. For deepseek-v4.1-flash: DeepSeek (China) 14.5%, DeepInfra 13.6%, StreamLake 1.4%, Morph 0.5%, SiliconFlow (Singapore) 0.1%.

Headquarters and data centers are as OpenRouter’s provider API lists them; the contracting entity can differ, as the endpoint table below shows. Shares come from each model page’s endpoint panels, which count one day of every customer’s traffic, whatever their settings, and change daily. The figure shows selected providers, so shares don’t sum to 100%.

Two things make this easy to miss.

The labels don’t always match the providers’ own terms. OpenRouter lists Baidu as Baidu Qianfan and marks it “Does not train.” The terms linked on Baidu’s listing are those of Baidu AI Cloud International. They define AI content as “the content you provide,” let Baidu use it “to develop, enhance, and improve AI services and their underlying technologies,” and let Baidu use non-personal content “to enhance the machine learning and AI technologies of Baidu AI Cloud and its affiliates.” Baidu’s international privacy policy adds that part of customers’ personal information is “stored on servers in China”; the terms don’t say where API content is processed.

Left: OpenRouter's panel for Baidu, listed as Baidu Qianfan, on deepseek-v4-flash, September 28, 2026, showing Prompt training: No and Headquarters: CN. Right: section 3A.3 of the Baidu AI Cloud International terms linked from that listing.

StreamLake is Kuaishou’s Singapore company. OpenRouter lists its headquarters as China and marks it as not training, while its terms let it “create, test, improve, train” its models on your input until you revoke by email. Kimi’s international terms say “Customer Content may be used” unless “otherwise expressly agreed in writing,” and StepFun’s international terms take a perpetual license to prompts “for any purpose.” OpenRouter says it sometimes negotiates stricter terms with providers, but none of these agreements is public, so a customer can’t check which terms govern its traffic.

Price drives routing, and shares swing within days. On September 26, Baidu was tied for third-cheapest of 16 endpoints for deepseek-v4-flash and carried 37.7% of that day’s tokens. On September 28, with Baidu and StreamLake both showing discounts of about 40%, Baidu carried under 2% and StreamLake about 36%. Together the two China-headquartered providers carried 45% and then 38%. OpenRouter’s privacy policy notes that it “cannot control Model Provider-side training once user data is transmitted to a training-permitted Model Provider.”

Other gateways behave similarly. Vercel AI Gateway “does not route based on the training data policy of providers” by default, and Together’s passthrough models, which it enables by default, mean Together “forwards your prompts and responses directly to the upstream provider.”

What do free AI models take in return?

Often your prompts. OpenRouter’s help center says “Most free endpoints train on, or may publish, the prompts they receive,” and to use free models it tells you to turn on “Free endpoints that may train on request data.” It doesn’t document whether that setting is on for new accounts. OpenRouter’s own flags on September 28, 2026, showed a lower share: 10 of its 20 free endpoints train on prompts, and none publishes them. The ten come from NVIDIA, Thinking Machines, Poolside and Liquid, none of them Chinese, and Thinking Machines’ free-tier terms take a “perpetual” license “to train, fine-tune, evaluate, and improve” its models.

That day no free endpoint ran on a China-headquartered provider; the free Qwen and Ling models from Chinese labs ran on US providers flagged as not training.

What free model offers take in return. NVIDIA's free Nemotron endpoints and Thinking Machines' free tier (US) may use prompts to improve their models with no opt-out. Volcano Ark's reward program (China) and BytePlus's (Singapore) may use prompts, and opting out stops only future collection. Volcano Ark's default free quota does not use prompts. Zhipu bigmodel.cn's free models (China) may use prompts with no opt-out, while Z.ai (Singapore) does not. iFlytek Spark Lite and Meituan LongCat (China, no international edition found) may use prompts with no opt-out. SiliconFlow's mainland free models do not use prompts.

Can use prompts to improve is Yes when the terms let the provider use inputs to train, improve or optimize its models or services. iFlytek limits this to de-identified or anonymized data; Zhipu limits only model training to anonymized data. Intl edition is whether the company offers the same service through a separate international entity: Not found means we found none, and NA means the row is already a non-mainland service. Under Opt-out, Future only means opting out stops new collection while data already used stays licensed, and NA means the offer doesn’t use prompts.

Some free offers state the trade outright. Volcano Ark’s Collaboration Reward Program collects up to 5 million tokens of prompts and outputs per model per day and gives back the same number of free tokens the next day. The license is permanent, and data already used “cannot technically be withdrawn” (our translation). Third-party models such as DeepSeek, Kimi and GLM were in the program as of September 28, and its current period runs to September 30, 2026. BytePlus runs the same deal from Singapore under an “irrevocable … perpetual” license. Both programs are opt-in; Volcano Ark’s default free quota falls under standard terms that rule training out. OpenRouter’s stealth models, pre-release models listed under a code name, are free “in consideration for the provision of your User Content,” and OpenRouter may not disclose “the name or origin” of the provider.

Mainland-only free APIs mostly allow using prompts. Zhipu’s bigmodel.cn lists GLM-4.7-Flash as free. Its terms let Zhipu use data generated as you use the service to improve its products unless agreed otherwise, take a perpetual, sublicensable license to non-personal content, and allow training on anonymized data. Z.ai, Zhipu’s Singapore edition, offers the same model free and won’t use API content “for developing or improving Services unless you explicitly agree.”

iFlytek’s free Spark Lite and Meituan’s LongCat both let the provider use inputs and outputs to optimize its services, with no real opt-out: iFlytek’s only way to object is an IP-complaint email address, and LongCat’s license also covers “brand promotion” (our translation). LongCat’s English legal pages return 404, so users outside the mainland sign the Chinese-language contract. Anonymization addresses personal data, not the code, contracts or product plans in a prompt.

Mainland terms don’t always allow training. SiliconFlow’s mainland policy rules out using business data for “any pre-training, fine-tuning” (our translation), and Kuaishou’s mainland platform, Vanchin, rules out training without written consent.

Which Chinese-origin model endpoints keep data in China or train on it?

DeepSeek’s API and the mainland editions of Kimi, Zhipu, Alibaba, Volcano Ark and Tencent process data in China. Eight endpoints don’t rule out training, and five of those are international editions. The same company often runs an international edition and a mainland edition through different entities on different terms.

Fifteen API endpoints for Chinese-origin models. DeepSeek, Kimi mainland, Zhipu bigmodel.cn, Alibaba Beijing, Baidu Qianfan mainland, Volcano Ark and Tencent Hunyuan contract through Chinese companies; all but Baidu state processing in China. Kimi, Z.ai, Alibaba, MiniMax, BytePlus and StreamLake international services are Singapore companies, StepFun's is a Hong Kong company, and Baidu AI Cloud International contracts through a British Virgin Islands subsidiary of Baidu. Terms rule out training for Z.ai, both Alibaba regions, Baidu Qianfan mainland, Volcano Ark and BytePlus; they don't for DeepSeek, both Kimi editions, Zhipu mainland, MiniMax, StepFun, Baidu AI Cloud International or StreamLake, and Tencent Hunyuan is unclear.

“Terms rule out training” is Yes only when the provider’s API terms or privacy policy say it won’t train on API data without your consent. Account life means data is kept while your account exists; As needed means no fixed period; Flagged only means only inputs that trip safety filters are kept; Flagged 180d means those inputs are kept 180 days; Contract +30d means deleted within 30 days after the contract ends; Not stored means API content isn’t retained; Unclear means the terms don’t say. MY / ID are Malaysia and Indonesia; BVI is the British Virgin Islands, where Baidu’s SEC filings place Baidu Holdings Limited, the entity behind Baidu AI Cloud International. The Baidu Qianfan mainland agreement doesn’t state a processing location.

Chinese origin does not mean Chinese processing. Alibaba’s international Model Studio runs inference on “global nodes excluding Chinese mainland” and “will never use your data for model training,” and Z.ai processes API data in Singapore, although its parent, Zhipu, has been on the US Commerce Department’s Entity List, an export-control list, since January 2025. For US data, these Singapore entities belong to Chinese groups, as does Baidu’s BVI entity, and that ownership matters under the Justice Department rule below.

An international edition is not automatically stricter. Baidu’s and Kuaishou’s international terms allow training that their mainland terms rule out. Kimi’s international service, run from Singapore, may use customer content unless “otherwise expressly agreed in writing.” MiniMax’s international service runs in the US but may use input “to provide, maintain, develop, and improve our Services.”

For US companies the question is the Justice Department’s data security rule; for EU data it’s GDPR’s transfer rules, under which Berlin’s regulator has already found the DeepSeek app’s transfers of user data to China unlawful.

The US data security rule. The Justice Department’s rule implementing Executive Order 14117 treats a company organized in China, Hong Kong included, or with its principal place of business there as a “covered person.” A company 50% or more owned by such companies is covered too, even one in Singapore. An API is a “vendor agreement,” which the rule defines as an arrangement to provide goods or services, including “cloud-computing services,” “in exchange for payment or other consideration,” so a free tier paid for with your data likely counts too. A vendor agreement giving a covered person access to bulk US sensitive personal data is a restricted transaction: it must meet security requirements set by CISA (the US Cybersecurity and Infrastructure Security Agency), in force since April 8, 2025, and since October 6, 2025, it also needs a written compliance program and an audit.

Bulk thresholds run from more than 100 US persons for genomic data to more than 100,000 for covered personal identifiers, counted over 12 months. CISA’s requirements aim to block covered-person access to data that is “linkable, identifiable, unencrypted, or decryptable,” which is hard to achieve when the API must read prompts in clear text. DOJ hasn’t published guidance on AI APIs or said how the rule treats a gateway’s customer; this reading is ours. Separately, the FY2026 National Defense Authorization Act bars Defense Department contractors from using DeepSeek models “with respect to the performance of a contract”; because the ban turns on who developed the model, self-hosted copies appear to be covered too.

GDPR transfers. China has no EU adequacy decision (the EU’s finding that a country protects personal data adequately), so transfers need safeguards such as standard contractual clauses (SCCs) plus a transfer impact assessment. For processors that need “access to the data in the clear,” the EDPB says it is “incapable of envisioning an effective technical measure” against disproportionate public-authority access. Berlin’s data protection commissioner reported DeepSeek’s app to Apple and Google in June 2025, finding that “Chinese authorities have extensive access rights.”

Chinese law. China’s National Intelligence Law and Data Security Law require organizations to support and cooperate with state intelligence and law-enforcement data requests. They bind the Chinese company wherever its customers are.

How much control do you get by deploying the model yourself?

More than with any shared API, but only after you change defaults. Running an open-weight model on your own infrastructure or a GPU cloud lets you pick the region, decide what your code logs and keep the model developer out of the data path.

Gateway (OpenRouter)Hosted APISelf-deployment
Who picks the providerGatewayYouYou
RegionGlobal by defaultHost decidesYou pick (default often global)
Training on your dataDepends on routeDepends on termsNot by the model developer
Payload loggingVariesVariesYour code plus platform logs
EffortLowLowHigh

Self-deployment options. Bedrock Custom Model Import runs in the US and EU with no operator access and no payload logging. SageMaker and Azure ML log payloads only if you opt in. Vertex keeps container logs on by default. Baseten keeps application logs and can query them remotely. Together's dedicated endpoints inherit an organization default that stores prompts. Hugging Face Endpoints keep logs 30 days and Runpod 90 days. Modal routes inputs through the US and accesses data only with your permission. CoreWeave and Vertex gate vendor access only if you opt in. Azure ML, Baseten and Together can run in your own cloud account, and Fireworks offers it in preview. Alibaba PAI-EAS offers regions including mainland China.

Payload means request and response bodies. Logs on, App logs and Logs in US mean the platform keeps container or application logs by default (in the US, for Modal); Logs 30d and Logs 90d are how long it keeps your container’s output. No access means no operator access to payloads; Opt-in gate means the vendor offers an approval step for staff access that you must turn on; Permission means staff access requires your permission by default; Remote logs means vendor staff can query your logs; Logged means staff access is logged but not gated; Terms only means access limits exist only in the contract. Multi means several regions to choose from and Via US means inputs pass through the US. Dedicated GPUs is whether you can get GPUs not shared with other customers; Opt-in there means as a paid option.

Defaults still decide a lot: Fireworks and Baseten default to global placement, and container logs become a new copy of your prompts, which CloudWatch keeps indefinitely by default even in your own AWS account. Vendor access is mostly procedural; even Baseten’s self-hosted option says “Some platform data does” leave your environment. Bedrock Custom Model Import is the exception by design: AWS says Bedrock uses a zero operator access model under which no service operators can access model inputs or outputs, apart from automated abuse detection.

Which gateway and tracing defaults keep data longer than needed?

Logs and traces are chosen features, but their default retention often outlasts the need.

  • Gateway logs without an end date. Cloudflare AI Gateway logs are “enabled by default for each gateway,” and accounts that created a gateway before September 24, 2026, keep logs “until you delete them.” LiteLLM sends prompts to every configured logging callback unless you set turn_off_message_logging, and its exact-match cache doesn’t separate entries by customer, so identical prompts from different tenants can get the same cached answer.
  • Tracing copies that outlive retention. LangSmith’s new evaluators and automation rules extend trace retention from 14 to 180 days by default, and traces added to a dataset “will never be deleted.” Langfuse says “project data retention does not delete audit logs or dataset items.”

What should you check before deploying?

If you do one thing today, block the providers your data can’t go to with OpenRouter’s ignore list and log which provider served each request. Nine checks cover most of the risks above:

  • On OpenRouter, set data_collection: "deny" and zdr: true. The zero-retention list still includes China-headquartered Tencent and Singapore companies of Chinese groups, so add providers your data can’t go to the account-level ignore list.
  • In OpenRouter’s account settings, turn off both the paid and the free switch for providers that may train (OpenRouter doesn’t document their defaults), and log which provider served each request.
  • Before production traffic reaches a provider, read the provider’s own terms, not only the gateway’s label.
  • Keep company and customer data away from free endpoints, stealth models and reward programs that trade tokens for data; use them only with synthetic or public data.
  • For Chinese-origin models, pin the endpoint: a US host, Bedrock or your own deployment (Defense Department contractors can’t use DeepSeek models even self-hosted). Where the DOJ rule doesn’t apply, an international edition whose terms rule out training is another option.
  • Before sending US personal data, check whether the provider is a covered person under the DOJ rule (organized or headquartered in China or Hong Kong, or at least 50% owned by such companies) and whether your volumes cross the bulk thresholds.
  • If EU personal data can reach a China-headquartered endpoint, block that route or put SCCs and a transfer impact assessment in place.
  • On self-deployment platforms, pin the region, turn off organization-level storage, and check where container logs go and how long they stay.
  • Turn off gateway body logging or set a retention period, put a tenant ID in cache keys, and set retention on tracing platforms.

FAQ

Does OpenRouter send my prompts to China?

It can. OpenRouter’s default settings don’t exclude China-headquartered providers. In our one-day readings, DeepSeek’s own endpoint, labeled as training on prompts, served 13% to 15% of deepseek-v4.1-flash tokens, and Baidu and StreamLake together served 38% to 45% of deepseek-v4-flash tokens. Blocking those providers with ignore removes them from routing; zdr: true alone doesn’t keep prompts away from Chinese groups, because OpenRouter’s zero-retention list includes Tencent and the Singapore companies of Moonshot, MiniMax, Zhipu and ByteDance.

Do free AI models train on my prompts?

Many free AI models do. OpenRouter’s own flags on September 28, 2026, showed 10 of its 20 free endpoints training on prompts, and the free tiers of NVIDIA, Thinking Machines, Zhipu’s mainland platform, iFlytek and Meituan’s LongCat all let the provider use prompts to improve its models or services.

Key sources: OpenRouter provider routing, provider logging, free model data settings, stealth model terms; Baidu AI Cloud International terms and privacy policy; DeepSeek open platform terms, model and training disclosure; BytePlus data collaboration terms; Zhipu user agreement; DOJ data security rule; EDPB Recommendations 01/2020; Berlin data protection commissioner on DeepSeek; Baseten self-hosted. Other values in the figures draw on each vendor’s docs, terms and privacy policy as of September 25 to 28, 2026.

Series: privacy across the AI supply chain

  1. AI Data Compliance Map: The 10 Places a Prompt Gets Stored
  2. LLM API Privacy Due Diligence: 3+ of 13 Train or Improve on Your Data
  3. AI Coding Agent Privacy: Don’t Trust the Toggle
  4. AI Agent Privacy: The Nine Data Channels Beyond the Prompt
  5. AI Gateway Privacy: Your Prompts Can Reach China and Train Models (this article)

This is an engineering and compliance reading of vendor terms, not legal advice.

Related reading