GenAgent Trust Hub
Menu

Mistral

BTier BLow risk · 51/100
  • Your data trains their AI unless you switch it off in settings.
  • The policy rules out using your data for targeted ads.
  • Data is shared only with the providers who run the service.
  • The documents do not say who can read your content.

They collect chats and usage, train unless you opt out in settings, and commercial terms cap and bar refunds.

Highest riskMedium riskLow risk

Agent Trust Hub uses AI and may make mistakes. Review reports and confirm their contents before relying on them.

Privacy policy ↗Terms ↗15 min read · professional or legal expert level28 lines verified word for word

Collected

What is collected

Name, email, payments, your prompts and outputs, device logs, usage, and some public or partner data.

Read the exact line

Privacy policy

““Technical Data”, any log or technical data that your browser and device automatically send when you use the Mistral AI Products, such as your IP address or the type of network protocol you use.”

Training

How it is used

They run the product, personalize Memory, debug, and train models on your chats unless you opt out.

Read the exact line

Privacy policy

“To train our artificial intelligence models (large language models) to answer questions, generate text, translate, summarize and correct text, classify text, analyze feelings, etc. according to context, Inputs (e-mails, letters, reports, computer code, etc.) and Outputs.”

Sharing

Who may see it

Staff, banks, regulators, lawyers, and service providers can get data; they say they do not sell it.

Read the exact line

Privacy policy

“No Sale, Sharing, or Targeted Advertising. Mistral AI has not “sold,” “shared,” or engaged in “targeted advertising” with (as those terms are defined under U.S. state privacy laws) any personal data of consumers in the preceding 12 months”

Kept

How long it is kept

Vibe chats last until you delete them; some API logs last 30 days; identity can stay years after you leave.

Read the exact line

Privacy policy

“Data we use to provide Vibe to you: we keep your Input and Output until you delete your account or until you delete the conversation from Vibe.”

Controls

Your controls

You can export data, delete your account, turn off Memory, and opt out of training in settings.

Read the exact line

Privacy policy

“We’ve introduced a user control which allows you to object to the use of your input and output data for model training directly from your account.”

Fine print

The fine print

Commercial users: they can cut access immediately, fees are non-refundable, and you them.

Read the exact line

Terms of service

“All amounts paid by Customer are non-refundable, non-cancellable, and non-creditable.”

Expand “Read the exact line” to see the source alongside the explanation.

What you can turn off

The controls and opt-outs their own documents describe, and where they say to find them.

  1. Turn off model training

    Mistral AI Account settings (Help Center describes the user control)

  2. Turn off or edit Knowledge Base / Memory

    Your settings on Vibe / Help Center for Knowledge Base controls

  3. Export your data then delete the account

    User controls in Mistral AI Account settings

  4. Opt out of IP-based personalization

    User preferences on your Mistral AI Account

If a switch is not where they say, the deletion request above still applies.

Line by line

The lines that matter most, worst first.

1 · How it is used

They use your chats and ratings to train AI unless you turn that off.

Read the exact line

Privacy policy

“Your Input and Output, subject to your opt-out. Your Feedback.Our in developing and providing state-of-the-art large language models as part of the Mistral AI Products.”

For example, a private prompt you typed could be used to improve their next model if you never flipped the training switch.

2 · How it is used

Experimental models ignore your training opt-out.

Read the exact line

Terms of service

“By using Labs or Preview Models, you acknowledge that (i) Mistral AI may use Customer Data and Outputs generated from Labs or Preview Models to train its artificial intelligence models”

For example, trying a “labs” model can send that chat into training even if you opted out elsewhere.

3 · The fine print

If someone sues over your use or your data, you may have to pay Mistral’s legal bills.

Read the exact line

Terms of service

“Customer will , defend, and hold Mistral AI and its affiliates and licensors harmless against any liabilities, damages, and costs (including reasonable attorneys’ fees)”

For example, if a prompt you uploaded causes a lawsuit, you could owe their lawyer fees.

4 · The fine print

They can shut you off right away for breach, unpaid bills, law, or risk they see.

Read the exact line

Terms of service

“Mistral AI reserves the right to immediately suspend or terminate Customer’s Mistral AI account or Customer’s access to all or part of the Mistral AI Products”

For example, they could lock the workspace the same day they think a policy was broken.

5 · The fine print

Money you pay is kept even if you stop using the product.

Read the exact line

Terms of service

“All amounts paid by Customer are non-refundable, non-cancellable, and non-creditable.”

For example, unused API credits after you cancel would not come back.

6 · How long it is kept

Your name can stay on file for five years after you close the account.

Read the exact line

Privacy policy

“Your Civil Identity Data (your first and last name, etc.): for 5 years after the termination of your Mistral AI account.”

For example, deleting the account does not wipe your legal name from their records immediately.

7 · How it is used

On the commercial terms, you own what you put in and what the model writes back.

Read the exact line

Terms of service

“Customer (i) retains all ownership rights in Customer Data and (ii) owns all Output. Mistral AI hereby assigns to Customer all right, title, and interest, if any, in and to Output”

For example, code the model generates for your company is treated as yours.

8 · How long it is kept

Memory/Knowledge Base can be switched off and edited by you.

Read the exact line

Privacy policy

“You can: Turn off the feature at all times through your settingsAccess, add, delete or edit your Memories or your Knowledge Base at all time through your settings.”

For example, you can delete a saved fact about your job from Knowledge Base.

9 · How it is used

They say they have not sold U.S. consumer data or used it for targeted ads in the last year.

Read the exact line

Privacy policy

“Mistral AI has not “sold,” “shared,” or engaged in “targeted advertising” with (as those terms are defined under U.S. state privacy laws) any personal data of consumers in the preceding 12 months”

For example, they claim they are not selling your chat profile to ad networks.

10 · The fine print

The privacy policy has no date and they tell you to keep checking it yourself.

Read the exact line

Privacy policy

“We may amend this Privacy Policy from time to time as our products continuously evolve. Make sure to check this Privacy Policy frequently.”

For example, training rules could change without a clear email to you.

Words to know

Legal words from the lines above, in plain English.

inputs and outputs
Inputs are what you type, say or upload to an AI; outputs are what it gives back to you. For example, the question you ask a chatbot is an input and its answer is an output, and both may be stored.
targeted advertising
Ads chosen for you based on what you have done across other apps and websites, not just this one. For example, you look at shoes in one app and see shoe ads in a totally different app the next day.
personal data
Any information that is about you or can be linked to you, from your name to your phone's ID. For example, your email, your IP address and the list of apps on your phone are all personal data.
model training
Using your content and conversations as examples to teach an AI system, which can then echo them in future answers. For example, a story you write in a chatbot may be studied by the company to make the next version of the bot.
opt out
Something is on by default and stays on until you find the setting and turn it off. For example, your chats may be used for training unless you go into settings and switch it off.
legitimate interest
A legal reason that lets a company use your data without asking, when it decides its own need outweighs your privacy. For example, an app may analyse how you use it to improve the product, without ever asking you.
indemnify
You promise to pay the company's legal costs and losses if your use of the service gets it sued. For example, if you post a song you do not own and the label sues the app, you owe the app's lawyer bills.
affiliates
Other companies owned by or connected to the same parent company. For example, if you use one app, its sister apps under the same owner may also get your data.
How we got here · grade B · score 51/100 · 15 of 15 policy answers backed by a verified quote · 2 not stated
  • What does the app collect beyond what it needs to work?

    They collect account and payment details, your prompts and outputs, plus technical logs like IP address and usage data.

  • Does it record your voice, face or body, and what happens to that?

    Not stated in the documents.

  • Are your chats and uploads used to train AI models, and is that off by default?

    Training on your input and output is described as subject to opt-out from your account settings. Labs/preview models still train.

  • Can employees or contractors read your conversations, and when?

    Not stated in the documents.

  • Are you profiled or tracked for advertising?

    For U.S. users they say they have not engaged in targeted advertising; cookies are covered in a separate cookie policy.

  • Do they sell or share your data, and can you opt out?

    They share with team members, banks, authorities, lawyers, and audited service providers, and say they do not sell U.S. consumer data.

  • What rights do they take over what you type and what the AI makes?

    Commercial terms say you keep ownership of inputs and own outputs; they take a license to run the service and, if allowed, to train.

  • How long do they keep your data after you delete it, and can you delete it in the app?

    You can delete chats and your account in the product, but some identity and invoice data is kept for years after you leave.

  • Does it build a lasting memory or profile of you, and can you see, edit or turn it off?

    Vibe Memory/Knowledge Base personalizes answers; you can turn it off and view, add, edit, or delete memories in settings.

  • Do they commit to basic security, and have they leaked data?

    They say they audit providers, use certifications, and list providers on a Trust Center, but no independent audit details are in these pages.

  • Is there a real age gate, and are teens protected?

    Commercial terms ban children’s personal information under 13 without parental consent; there is no described age-check process.

  • Will they tell you when the rules change, and is the policy specific?

    The privacy policy has no date and tells you to check it often. Commercial terms promise 30-day notice of material changes.

  • Can they close your account without warning, and can you get your data out first?

    They may immediately suspend or terminate commercial access; you must export data before the account is closed.

  • If something goes wrong, who pays?

    Products are as-is, liability is capped at twelve months of fees, and the customer must indemnify Mistral for many third-party claims.

  • Do subscriptions renew on their own, and can you get a refund?

    Fees can be charged monthly to the payment method and all amounts are non-refundable and non-cancellable.

The privacy policy is 3,448 words at a professional or legal expert level (Flesch reading ease 21.9); the terms are 6,457 words at a professional or legal expert level.

Your privacy
has an agent now

Be in control of your online privacy in the AI Era with confidence.

Gen

From Gen, the Company BehindNorton