Their privacy policy doesn't forbid them from just straight up publishing your raw prompts as training data.
My threat model is that anything I POST to DeepSeek I treat as public to the web, as much as a public GitHub repo is.