Mistral AI trains its AI models using datasets from third parties and publicly available internet data, which may contain your personal information even after filtering attempts.
This analysis describes what Mistral AI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The provision establishes transparency regarding data sources used in model training and acknowledges that personal data may be present in training datasets despite filtration practices. This disclosure defines the scope of data processing activities that support the organization's core operations.
The updated policy now explicitly includes data accessed through third-party services and integrations users connect to Mistral AI Products as 'Input' data subject to collection and use. The policy removed its prior statement that Input and Output data are not used to train AI models when using Le Chat Enterprise or paid versions of Mistral APIs. This creates operational ambiguity: users of paid services and Enterprise customers no longer have a documented commitment that their data will be excluded from model training, though the privacy policy does not affirmatively state that model training now occurs. The policy also changed language describing product improvement from 'aggregated and anonymous statistics' to 'aggregated or anonymous datasets or statistics,' broadening the stated scope of what can be collected for improvement purposes.
View change record →Personal data about you that exists publicly online — such as on social media, news articles, or public records — may have been used to train Mistral AI's models, and there is no guarantee it was successfully filtered out despite stated efforts.
How other platforms handle this
Some features of our Services may use third-party automated technology to provide a more personalized experience, and to give you comprehensive insights about your data.
This is still Your Content, and you are responsible for it and its accuracy, as well as your use of it on our Services and any and all decisions made, actions taken, and failures to take action based on Your Content.
Due to the nature of the AI Features, generated Marketing Content may not be unique across users and the AI Features may generate the same or similar Marketing Content for other users.
"Training Datasets. In some cases, we access datasets provided by third parties for our model training purposes. These datasets may include personal data (even if such third parties and Mistral AI use good practices to filter out such personal data), proprietary data, or public data. [...] Data publicly available on the Internet. Our artificial intelligence models are trained on data that is publicly available on the Internet by third parties, which may contain personal data, even if we use good practices to filter out such personal data.Excerpt from Mistral AI's Privacy Policy
(1) REGULATORY FRAMEWORK: This provision implicates GDPR Art.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
How Meta, TikTok, and Supabase restructured governance language across documents, jurisdictions, and consent frameworks through incremental document updates.
How 10 AI platforms describe the use of user data for model training, improvement, and development, based on archived governance provisions.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The provision establishes transparency regarding data sources used in model training and acknowledges that personal data may be present in training datasets despite filtration practices. This disclosure defines the scope of data processing activities that support the organization's core operations.
Personal data about you that exists publicly online — such as on social media, news articles, or public records — may have been used to train Mistral AI's models, and there is no guarantee it was successfully filtered out despite stated efforts.
ConductAtlas has identified this type of provision across 217 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Mistral AI.