Mistral
- Your data trains their AI unless you switch it off in settings.
- The policy rules out using your data for targeted ads.
- Data is shared only with the providers who run the service.
- The documents do not say who can read your content.
They collect chats and usage, train unless you opt out in settings, and commercial terms cap and bar refunds.
Agent Trust Hub uses AI and may make mistakes. Review reports and confirm their contents before relying on them.
Collected
Name, email, payments, your prompts and outputs, device logs, usage, and some public or partner data.
Read the exact line
Privacy policy
““Technical Data”, any log or technical data that your browser and device automatically send when you use the Mistral AI Products, such as your IP address or the type of network protocol you use.”
Training
They run the product, personalize Memory, debug, and train models on your chats unless you opt out.
Read the exact line
Privacy policy
“To train our artificial intelligence models (large language models) to answer questions, generate text, translate, summarize and correct text, classify text, analyze feelings, etc. according to context, Inputs (e-mails, letters, reports, computer code, etc.) and Outputs.”
Sharing
Staff, banks, regulators, lawyers, and service providers can get data; they say they do not sell it.
Read the exact line
Privacy policy
“No Sale, Sharing, or Targeted Advertising. Mistral AI has not “sold,” “shared,” or engaged in “targeted advertising” with (as those terms are defined under U.S. state privacy laws) any personal data of consumers in the preceding 12 months”
Kept
Vibe chats last until you delete them; some API logs last 30 days; identity can stay years after you leave.
Read the exact line
Privacy policy
“Data we use to provide Vibe to you: we keep your Input and Output until you delete your account or until you delete the conversation from Vibe.”
Controls
You can export data, delete your account, turn off Memory, and opt out of training in settings.
Read the exact line
Privacy policy
“We’ve introduced a user control which allows you to object to the use of your input and output data for model training directly from your account.”
Fine print
Commercial users: they can cut access immediately, fees are non-refundable, and you them.
Read the exact line
Terms of service
“All amounts paid by Customer are non-refundable, non-cancellable, and non-creditable.”
Expand “Read the exact line” to see the source alongside the explanation.
What you can turn off
The controls and opt-outs their own documents describe, and where they say to find them.
Turn off model training
Mistral AI Account settings (Help Center describes the user control)
Turn off or edit Knowledge Base / Memory
Your settings on Vibe / Help Center for Knowledge Base controls
Export your data then delete the account
User controls in Mistral AI Account settings
Opt out of IP-based personalization
User preferences on your Mistral AI Account
If a switch is not where they say, the deletion request above still applies.
Line by line
The lines that matter most, worst first.
They use your chats and ratings to train AI unless you turn that off.
Read the exact line
Privacy policy
“Your Input and Output, subject to your opt-out. Your Feedback.Our in developing and providing state-of-the-art large language models as part of the Mistral AI Products.”
For example, a private prompt you typed could be used to improve their next model if you never flipped the training switch.
Experimental models ignore your training opt-out.
Read the exact line
Terms of service
“By using Labs or Preview Models, you acknowledge that (i) Mistral AI may use Customer Data and Outputs generated from Labs or Preview Models to train its artificial intelligence models”
For example, trying a “labs” model can send that chat into training even if you opted out elsewhere.
If someone sues over your use or your data, you may have to pay Mistral’s legal bills.
Read the exact line
Terms of service
“Customer will , defend, and hold Mistral AI and its affiliates and licensors harmless against any liabilities, damages, and costs (including reasonable attorneys’ fees)”
For example, if a prompt you uploaded causes a lawsuit, you could owe their lawyer fees.
They can shut you off right away for breach, unpaid bills, law, or risk they see.
Read the exact line
Terms of service
“Mistral AI reserves the right to immediately suspend or terminate Customer’s Mistral AI account or Customer’s access to all or part of the Mistral AI Products”
For example, they could lock the workspace the same day they think a policy was broken.
Money you pay is kept even if you stop using the product.
Read the exact line
Terms of service
“All amounts paid by Customer are non-refundable, non-cancellable, and non-creditable.”
For example, unused API credits after you cancel would not come back.
Your name can stay on file for five years after you close the account.
Read the exact line
Privacy policy
“Your Civil Identity Data (your first and last name, etc.): for 5 years after the termination of your Mistral AI account.”
For example, deleting the account does not wipe your legal name from their records immediately.
On the commercial terms, you own what you put in and what the model writes back.
Read the exact line
Terms of service
“Customer (i) retains all ownership rights in Customer Data and (ii) owns all Output. Mistral AI hereby assigns to Customer all right, title, and interest, if any, in and to Output”
For example, code the model generates for your company is treated as yours.
Memory/Knowledge Base can be switched off and edited by you.
Read the exact line
Privacy policy
“You can: Turn off the feature at all times through your settingsAccess, add, delete or edit your Memories or your Knowledge Base at all time through your settings.”
For example, you can delete a saved fact about your job from Knowledge Base.
They say they have not sold U.S. consumer data or used it for targeted ads in the last year.
Read the exact line
Privacy policy
“Mistral AI has not “sold,” “shared,” or engaged in “targeted advertising” with (as those terms are defined under U.S. state privacy laws) any personal data of consumers in the preceding 12 months”
For example, they claim they are not selling your chat profile to ad networks.
The privacy policy has no date and they tell you to keep checking it yourself.
Read the exact line
Privacy policy
“We may amend this Privacy Policy from time to time as our products continuously evolve. Make sure to check this Privacy Policy frequently.”
For example, training rules could change without a clear email to you.
Words to know
Legal words from the lines above, in plain English.
- inputs and outputs
- Inputs are what you type, say or upload to an AI; outputs are what it gives back to you. For example, the question you ask a chatbot is an input and its answer is an output, and both may be stored.
- targeted advertising
- Ads chosen for you based on what you have done across other apps and websites, not just this one. For example, you look at shoes in one app and see shoe ads in a totally different app the next day.
- personal data
- Any information that is about you or can be linked to you, from your name to your phone's ID. For example, your email, your IP address and the list of apps on your phone are all personal data.
- model training
- Using your content and conversations as examples to teach an AI system, which can then echo them in future answers. For example, a story you write in a chatbot may be studied by the company to make the next version of the bot.
- opt out
- Something is on by default and stays on until you find the setting and turn it off. For example, your chats may be used for training unless you go into settings and switch it off.
- legitimate interest
- A legal reason that lets a company use your data without asking, when it decides its own need outweighs your privacy. For example, an app may analyse how you use it to improve the product, without ever asking you.
- indemnify
- You promise to pay the company's legal costs and losses if your use of the service gets it sued. For example, if you post a song you do not own and the label sues the app, you owe the app's lawyer bills.
- affiliates
- Other companies owned by or connected to the same parent company. For example, if you use one app, its sister apps under the same owner may also get your data.
How we got here · grade B · score 51/100 · 15 of 15 policy answers backed by a verified quote · 2 not stated
What does the app collect beyond what it needs to work?
They collect account and payment details, your prompts and outputs, plus technical logs like IP address and usage data.
Does it record your voice, face or body, and what happens to that?
Not stated in the documents.
Are your chats and uploads used to train AI models, and is that off by default?
Training on your input and output is described as subject to opt-out from your account settings. Labs/preview models still train.
Can employees or contractors read your conversations, and when?
Not stated in the documents.
Are you profiled or tracked for advertising?
For U.S. users they say they have not engaged in targeted advertising; cookies are covered in a separate cookie policy.
Do they sell or share your data, and can you opt out?
They share with team members, banks, authorities, lawyers, and audited service providers, and say they do not sell U.S. consumer data.
What rights do they take over what you type and what the AI makes?
Commercial terms say you keep ownership of inputs and own outputs; they take a license to run the service and, if allowed, to train.
How long do they keep your data after you delete it, and can you delete it in the app?
You can delete chats and your account in the product, but some identity and invoice data is kept for years after you leave.
Does it build a lasting memory or profile of you, and can you see, edit or turn it off?
Vibe Memory/Knowledge Base personalizes answers; you can turn it off and view, add, edit, or delete memories in settings.
Do they commit to basic security, and have they leaked data?
They say they audit providers, use certifications, and list providers on a Trust Center, but no independent audit details are in these pages.
Is there a real age gate, and are teens protected?
Commercial terms ban children’s personal information under 13 without parental consent; there is no described age-check process.
Will they tell you when the rules change, and is the policy specific?
The privacy policy has no date and tells you to check it often. Commercial terms promise 30-day notice of material changes.
Can they close your account without warning, and can you get your data out first?
They may immediately suspend or terminate commercial access; you must export data before the account is closed.
If something goes wrong, who pays?
Products are as-is, liability is capped at twelve months of fees, and the customer must indemnify Mistral for many third-party claims.
Do subscriptions renew on their own, and can you get a refund?
Fees can be charged monthly to the payment method and all amounts are non-refundable and non-cancellable.
The privacy policy is 3,448 words at a professional or legal expert level (Flesch reading ease 21.9); the terms are 6,457 words at a professional or legal expert level.