Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
For API users, Mistral AI keeps your prompts and AI responses for 30 days after generation to monitor for abuse, unless you have activated zero data retention. Agents API data is kept until you close your account.
This analysis describes what Mistral AI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The provision creates differentiated retention schedules across API product lines, with standard APIs subject to the 30-day rolling window while specialized APIs (Agents and Fine-Tuning) maintain longer retention periods tied to account lifecycle events. This structure establishes the operational framework for data lifecycle management across Mistral's API offerings.
The updated policy now explicitly includes data accessed through third-party services and integrations users connect to Mistral AI Products as 'Input' data subject to collection and use. The policy removed its prior statement that Input and Output data are not used to train AI models when using Le Chat Enterprise or paid versions of Mistral APIs. This creates operational ambiguity: users of paid services and Enterprise customers no longer have a documented commitment that their data will be excluded from model training, though the privacy policy does not affirmatively state that model training now occurs. The policy also changed language describing product improvement from 'aggregated and anonymous statistics' to 'aggregated or anonymous datasets or statistics,' broadening the stated scope of what can be collected for improvement purposes.
View change record →If you or a business you use deploys Mistral AI's APIs, your conversation data is retained for up to 30 days for abuse monitoring unless the operator has enabled zero data retention — creating a window during which your data is accessible to Mistral AI.
How other platforms handle this
We collect and keep personal data only as needed or allowed for the purposes set out in this Statement, based on the reason we collected the personal data in the first instance and what is permitted under the laws that apply to the processing.
Affirm will retain your information in accordance with our Privacy Policy and any applicable state or federal law, rule or regulation.
Walmart does not retain any information prior to recognizing the "Hey, Walmart" utterance, and only uses information collected after hearing that utterance for limited purposes such as providing the service...
Monitoring
Mistral AI has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"Data we use to provide our APIs to you: Except for specific APIs, we keep your Input and Output for the period necessary to generate the Output and then for thirty (30) rolling days to monitor abuse (unless zero data retention is activated). If you use our Agents API, we keep your Input and Output until you terminate your account. If you use our Fine-Tuning API, we keep your fine-tuning data until you delete it from Mistral AI Studio or until you terminate your account.Excerpt from Mistral AI's Privacy Policy
(1) REGULATORY FRAMEWORK: This provision implicates GDPR Art. 5(1)(e) (storage limitation principle), which requires personal data be kept no longer than necessary for the stated purpose. The 30-day retention for abuse monitoring must be justified by a documented necessity assessment. GDPR Art. 28(3)(g) requires data processing agreements to specify retention and deletion obligations, making this provision directly relevant to DPA compliance for commercial API customers. (2)
Regulatory citations, enforcement risk, and due diligence action items.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
The provision creates differentiated retention schedules across API product lines, with standard APIs subject to the 30-day rolling window while specialized APIs (Agents and Fine-Tuning) maintain longer retention periods tied to account lifecycle events. This structure establishes the operational framework for data lifecycle management across Mistral's API offerings.
If you or a business you use deploys Mistral AI's APIs, your conversation data is retained for up to 30 days for abuse monitoring unless the operator has enabled zero data retention — creating a window during which your data is accessible to Mistral AI.
ConductAtlas has identified this type of provision across 275 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Mistral AI.