Mistral AI · Mistral AI Privacy Policy · View original document ↗

Memory Feature and Sensitive Data Storage

Medium severity Medium confidence Explicitdocumentlanguage Unique · 0 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Mistral AI recorded 4 documented changes in the last 30 days.
Start monitoring updates
Monitor governance changes for Mistral AI Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

Le Chat has a Memory feature that saves information from your past conversations to personalize future responses. If you mention health or other sensitive details in a prompt, that information may be stored and used to tailor answers to you.

This analysis describes what Mistral AI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

Sensitive personal data such as health information that you casually mention in a chat prompt could be automatically stored and retained by the Memory feature, creating a personal profile that persists across your Le Chat sessions.

Interpretive note: The policy states explicit consent governs sensitive data saved as Memories, but the specific mechanism for obtaining that consent before sensitive data from free-form prompts is saved is not described in sufficient detail to confirm GDPR compliance.

Consumer impact (what this means for users)

The Memory feature may store health or other sensitive personal details mentioned in prompts; the policy states explicit consent governs sensitive data in Memories, but users should actively review and manage their Memory settings to control what is retained.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Log into Le Chat, go to your account settings, navigate to the Memory section, and review, edit, or delete any stored Memories. You can also turn off the Memory feature entirely from this settings page.

Cross-platform context

See how other platforms handle Memory Feature and Sensitive Data Storage and similar clauses.

Compare across platforms →

Monitoring

Mistral AI has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
To enhance your experience on Le Chat via the Memory feature by providing you more relevant and personalized answers based on your past interactions with Le Chat. [...] Your Input (prompts). If you include sensitive data in your Input, such as health details, this data may be stored as a Memory to provide you with more relevant and personalized answers. [...] Your explicit consent for any sensitive data explicitly included in your input and saved as a Memory. You can: Access, add, delete or edit your Memories at all time through your settings. Turn off Memories at all times through your settings.

— Excerpt from Mistral AI's Mistral AI Privacy Policy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

1. REGULATORY LANDSCAPE: This provision engages GDPR's special category data rules, which require explicit consent and heightened protections for health data and other sensitive categories. The CNIL, as the lead supervisory authority for Mistral AI, would evaluate whether the consent mechanism for sensitive data in Memories is specific, informed, freely given, and unambiguous as required under GDPR. The EU AI Act's transparency requirements may also apply to AI systems that build persistent user profiles. 2. GOVERNANCE EXPOSURE: High. The mechanism by which explicit consent is obtained for sensitive data incidentally included in free-form chat prompts is not fully specified in this policy. Regulators may question whether a general notice in a privacy policy constitutes adequate explicit consent for special category data processing under GDPR. The distinction between 'explicitly included' sensitive data and incidentally mentioned sensitive data introduces interpretive ambiguity. 3. JURISDICTION FLAGS: EU and EEA users face heightened exposure given GDPR's strict requirements for special category data. Health data stored in Memories may also engage health data protection frameworks in other jurisdictions. Illinois BIPA would not directly apply unless biometric data is involved, but state-level health privacy laws may apply to US users. 4. CONTRACT AND VENDOR IMPLICATIONS: Organizations deploying Le Chat for employees or customers should assess whether the Memory feature's storage of employee or customer sensitive data creates additional data controller obligations or requires data processing agreements beyond standard terms. 5. COMPLIANCE CONSIDERATIONS: Legal teams should evaluate whether the consent mechanism for sensitive data in Memories meets GDPR's explicit consent standard, including whether users receive a specific, granular consent request before sensitive data is saved. A data mapping exercise should confirm how Memory data is stored, for how long, and whether it is segregated from other processing activities. User-facing controls (access, edit, delete, turn off) should be audited for ease of use and effectiveness.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Watcher free for 14 days

Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC has authority over deceptive or unfair practices related to health data collection and use by non-HIPAA-covered entities, including AI platforms that store health-related user information.
    File a complaint →

Provision details

Document information
Document
Mistral AI Privacy Policy
Entity
Mistral AI
Document last updated
May 5, 2026
Tracking information
First tracked
May 11, 2026
Last verified
May 11, 2026
Record ID
CA-P-007011
Document ID
CA-D-00443
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
a3774c814d80737846c7ac8379ec7dcc1c55ee8e0300de40dccee951ff5d0230
Analysis generated
May 11, 2026 05:55 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Mistral AI
Document: Mistral AI Privacy Policy
Record ID: CA-P-007011
Captured: 2026-05-11 05:55:06 UTC
SHA-256: a3774c814d807378…
URL: https://conductatlas.com/platform/mistral-ai/mistral-ai-privacy-policy/memory-feature-and-sensitive-data-storage/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Mistral AI's Memory Feature and Sensitive Data Storage clause do?

Sensitive personal data such as health information that you casually mention in a chat prompt could be automatically stored and retained by the Memory feature, creating a personal profile that persists across your Le Chat sessions.

How does this clause affect you?

The Memory feature may store health or other sensitive personal details mentioned in prompts; the policy states explicit consent governs sensitive data in Memories, but users should actively review and manage their Memory settings to control what is retained.

Is ConductAtlas affiliated with Mistral AI?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Mistral AI.