7 Total
0 High severity
4 Medium severity
3 Low severity
Stay ahead of the changes
Track Mistral AI and get the diff the day its terms change.
Summary

This document establishes Mistral AI's data processing practices for personal data collected through its products, including Le Chat and Mistral AI Studio. The policy authorizes the use of chat prompts and AI-generated responses for model training purposes under a legitimate interest legal basis, with this processing applied by default to free-tier users unless an opt-out election is made through account settings. The policy excludes paid API tiers and Le Chat Enterprise from this default model training use, and establishes separate processing terms for the Memory feature, which stores user-provided information including health data under an explicit consent requirement.

Analysis

This document is Mistral AI's Privacy Policy (effective April 8, 2026), governing personal data collection, use, and retention for consumer-facing products including Le Chat and Mistral AI Studio, with Mistral AI (a French company) acting as data controller under GDPR principles. The policy states it uses contractual necessity, legitimate interest, and consent as lawful bases for processing; notably, the terms authorize use of user Inputs and Outputs for AI model training under a legitimate interest basis unless users opt out, with an explicit carve-out stating that Le Chat Enterprise and paid API users are excluded from this training use. The training opt-out structure, reliance on legitimate interest rather than consent for model training, and the Memory feature's potential to store sensitive health data represent operationally distinct provisions; the policy asserts that sensitive data in the Memory feature is processed on explicit consent, though the degree to which incidental inclusion of sensitive data in prompts triggers adequate prior consent mechanisms warrants evaluation. As a French company with EU-based operations, this policy engages GDPR most directly, including obligations around data subject rights, lawful basis documentation, and DPO appointment; the EU AI Act may also require evaluation given Mistral AI's role as an AI model provider, and California residents may have additional rights under CCPA that are not explicitly addressed in this document.

What this means for you

Users of free-tier Mistral AI products operate under terms that authorize their chat inputs and outputs to be used for model training by default, with the burden of opt-out action placed on the user rather than requiring prior affirmative consent. The Memory feature's operation depends on explicit user consent for sensitive data categories, though the document does not specify the mechanics through which this consent is obtained or managed. Paid API and Le Chat Enterprise users are subject to different data processing terms that exclude the default model training authorization.

Institutional Analysis
Stay ahead of the changes

Institutional analysis available with Insight

Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.

2 important changes detected

3 versions captured · Last updated: July 2026

July 28, 2026

medium
What changed Mistral AI updated its privacy policy effective July 27, 2026, making several product name and operational clarifications. The company replaced references to 'Le Chat' with 'Vibe' across multiple sections describing data handling practices. The policy expanded its definition of 'Input' data to explicitly include data accessed through third-party integrations and services connected by users, and changed language describing product improvement datasets from 'aggregated and anonymous statistics' to 'aggregated or anonymous datasets or statistics.' The company removed a sentence stating that Input and Output data are not used to train AI models when using Le Chat Enterprise or paid APIs, and that third-party service data connected to Mistral products are not used for model training.
Why this matters The updated policy now explicitly includes data accessed through third-party services and integrations users connect to Mistral AI Products as 'Input' data subject to collection and use. The policy removed its prior statement that Input and Output data are not used to train AI models when using Le Chat Enterprise or paid versions of Mistral APIs. This creates operational ambiguity: users of paid services and Enterprise customers no longer have a documented commitment that their data will be excluded from model training, though the privacy policy does not affirmatively state that model training now occurs. The policy also changed language describing product improvement from 'aggregated and anonymous statistics' to 'aggregated or anonymous datasets or statistics,' broadening the stated scope of what can be collected for improvement purposes.
View full change record →
What changed Mistral AI corrected a typo in their privacy policy header on May 6, 2026. The text "Applicant Privacy POlicy" was changed to "Applicant Privacy Policy" (fixing the capitalization of "Policy"). This is a minor editorial correction with no material impact on your privacy rights or the company's data practices.
Why this matters This change is a spelling correction only and does not affect Mistral AI's privacy practices, data handling, or your rights. The company fixed a typo in the document navigation menu ("POlicy" to "Policy"), but the actual privacy policy terms remain unchanged. No action is needed on your part.
View full change record →

Featured, Medium severity
Featured, Low severity
Stay ahead of the changes

Monitoring

Mistral AI has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Stay ahead of the changes

Governance Intelligence

Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.

Cross-platform context

See how other platforms handle AI Model Training on Free-Tier User Inputs and Outputs and similar clauses.

Compare across platforms →
Archival ProvenanceSource & Archival Record
Last Captured July 28, 2026 00:52 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000443
Version ID CA-V-005311
SHA-256 53ce94df338ef414b0e74cea9e503d2669b74fd8fe645e7662d95de9afbe6a49
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.

Start monitoring → Compare plans