Provision record
Mistral AI · Mistral AI Privacy Policy · View original document ↗

Data Retention — API Input/Output 30-Day Rolling Window

Medium severity Common · 275 of 352 platforms
Stay ahead of the changes
Track Mistral AI and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Mistral AI recorded 2 documented changes in the last 30 days.
Follow Mistral AI →
Monitor governance changes for Mistral AI Monitor emails you the same day this changes. The archive stays free.
Follow Mistral AI →

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

This analysis describes what Mistral AI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

The provision creates differentiated retention schedules across API product lines, establishing operational periods during which Mistral AI maintains access to input and output data for service delivery, abuse detection, and account-based services. The authorization for zero data retention represents an alternative configuration users may elect.

Recent Activity

This document changed recently

Medium Jul 28, 2026

The updated policy now explicitly includes data accessed through third-party services and integrations users connect to Mistral AI Products as 'Input' data subject to collection and use. The policy removed its prior statement that Input and Output data are not used to train AI models when using Le Chat Enterprise or paid versions of Mistral APIs. This creates operational ambiguity: users of paid services and Enterprise customers no longer have a documented commitment that their data will be excluded from model training, though the privacy policy does not affirmatively state that model training now occurs. The policy also changed language describing product improvement from 'aggregated and anonymous statistics' to 'aggregated or anonymous datasets or statistics,' broadening the stated scope of what can be collected for improvement purposes.

View change record →

Clause Stability Stable

0
Changes
3
Months Monitored
May 8, 2026
First Seen
May 8, 2026
Last Seen
This clause type exists across 1629 other provisions on other platforms.

Consumer impact (what this means for users)

Users' API inputs and outputs remain retained by Mistral AI under the stated schedule unless they activate zero data retention; for Agents and Fine-Tuning APIs specifically, data retention extends through account lifecycle or until explicit deletion by the user. The terms authorize a rolling 30-day post-processing retention window for standard API usage to support abuse monitoring.

How other platforms handle this

Palantir Medium

We collect and keep personal data only as needed or allowed for the purposes set out in this Statement, based on the reason we collected the personal data in the first instance and what is permitted under the laws that apply to the processing.

Affirm Medium

Affirm will retain your information in accordance with our Privacy Policy and any applicable state or federal law, rule or regulation.

Walmart Medium

Walmart does not retain any information prior to recognizing the "Hey, Walmart" utterance, and only uses information collected after hearing that utterance for limited purposes such as providing the service...

See all platforms with this clause type →

Monitoring

Mistral AI has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Follow Mistral AI → Or get the research letter, free →
▸ View Original Clause Language DOCUMENT RECORD
"
Data we use to provide our APIs to you: Except for specific APIs, we keep your Input and Output for the period necessary to generate the Output and then for thirty (30) rolling days to monitor abuse (unless zero data retention is activated). If you use our Agents API, we keep your Input and Output until you terminate your account. If you use our Fine-Tuning API, we keep your fine-tuning data until you delete it from Mistral AI Studio or until you terminate your account.

Excerpt from Mistral AI's Privacy Policy

Applicable regulations

CCPA/CPRA
California, USA
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN

Provision details

Document information
Document
Mistral AI Privacy Policy
Entity
Mistral AI
Document last updated
May 5, 2026
Tracking information
First tracked
May 11, 2026
Last verified
May 11, 2026
Record ID
CA-P-007012
Document ID
CA-D-00443
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
a3774c814d80737846c7ac8379ec7dcc1c55ee8e0300de40dccee951ff5d0230
Analysis generated
May 11, 2026 05:55 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Mistral AI
Document: Mistral AI Privacy Policy
Record ID: CA-P-007012
Captured: 2026-05-11 05:55:06 UTC
SHA-256: a3774c814d807378…
URL: https://conductatlas.com/platform/mistral-ai/mistral-ai-privacy-policy/provision/CA-P-007012/data-retention-api-inputoutput-30-day-rolling-window/
Accessed: July 28, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Stay ahead of the changes

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention

Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.

Frequently Asked Questions

What does Mistral AI's Data Retention — API Input/Output 30-Day Rolling Window clause do?

The provision creates differentiated retention schedules across API product lines, establishing operational periods during which Mistral AI maintains access to input and output data for service delivery, abuse detection, and account-based services. The authorization for zero data retention represents an alternative configuration users may elect.

How does this clause affect you?

Users' API inputs and outputs remain retained by Mistral AI under the stated schedule unless they activate zero data retention; for Agents and Fine-Tuning APIs specifically, data retention extends through account lifecycle or until explicit deletion by the user. The terms authorize a rolling 30-day post-processing retention window for standard API usage to support abuse monitoring.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 275 platforms. See the full comparison.

Is ConductAtlas affiliated with Mistral AI?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Mistral AI.