Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This page describes what the document states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability may vary by jurisdiction. Methodology
This document establishes Mistral AI's data processing practices for personal data collected through its products, including Le Chat and Mistral AI Studio. The policy authorizes the use of chat prompts and AI-generated responses for model training purposes under a legitimate interest legal basis, with this processing applied by default to free-tier users unless an opt-out election is made through account settings. The policy excludes paid API tiers and Le Chat Enterprise from this default model training use, and establishes separate processing terms for the Memory feature, which stores user-provided information including health data under an explicit consent requirement.
This document is Mistral AI's Privacy Policy (effective April 8, 2026), governing personal data collection, use, and retention for consumer-facing products including Le Chat and Mistral AI Studio, with Mistral AI (a French company) acting as data controller under GDPR principles. The policy states it uses contractual necessity, legitimate interest, and consent as lawful bases for processing; notably, the terms authorize use of user Inputs and Outputs for AI model training under a legitimate interest basis unless users opt out, with an explicit carve-out stating that Le Chat Enterprise and paid API users are excluded from this training use. The training opt-out structure, reliance on legitimate interest rather than consent for model training, and the Memory feature's potential to store sensitive health data represent operationally distinct provisions; the policy asserts that sensitive data in the Memory feature is processed on explicit consent, though the degree to which incidental inclusion of sensitive data in prompts triggers adequate prior consent mechanisms warrants evaluation. As a French company with EU-based operations, this policy engages GDPR most directly, including obligations around data subject rights, lawful basis documentation, and DPO appointment; the EU AI Act may also require evaluation given Mistral AI's role as an AI model provider, and California residents may have additional rights under CCPA that are not explicitly addressed in this document.
Users of free-tier Mistral AI products operate under terms that authorize their chat inputs and outputs to be used for model training by default, with the burden of opt-out action placed on the user rather than requiring prior affirmative consent. The Memory feature's operation depends on explicit user consent for sensitive data categories, though the document does not specify the mechanics through which this consent is obtained or managed. Paid API and Le Chat Enterprise users are subject to different data processing terms that exclude the default model training authorization.
Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.
2 important changes detected
3 versions captured · Last updated: July 2026
Mistral AI has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.
Cross-platform context
See how other platforms handle AI Model Training on Free-Tier User Inputs and Outputs and similar clauses.
Compare across platforms →Governance Monitoring
Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.