Mistral AI
mistral.aiMistral AI is a French generative-AI provider whose consumer-facing documents give users strong ownership of their inputs and outputs, GDPR-grounded data rights, and — importantly — an explicit opt-out from model training plus user controls for deletion, export and objection. The most significant residual risk for consumers is that free-tier, Vibe Pro and Vibe Student data IS used to train Mistral's models unless the user opts out, and that 'sensitive data' voluntarily included in prompts may be stored as a 'Memory'. Compliance disclosure is weak: the documents reference a Trust Center and 'certifications' but name no specific attestation (SOC 2, ISO 27001, ISO 42001) in the supplied text, and only one of the supplied documents (the Privacy Policy) speaks to data collection in detail. Overall the consumer posture is moderate — favourable ownership and rights, but training-by-default and thin security/compliance evidence warrant caution before submitting sensitive or proprietary data.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
The consumer terms are explicit that the user retains all ownership rights in their Input. Mistral takes only a license to use the data for defined purposes, not ownership.
Output Data Ownership
Users own all Output, and Mistral affirmatively assigns any interest it may have in the Output to the user. A caveat is that Outputs are not guaranteed to be unique and may be identical to other users' results.
Training Data Usage
Mistral trains its models on user Input and Output by default for free-tier, Vibe Pro and Vibe Student users unless they opt out, and always uses Feedback (and its associated Input/Output) for training. An opt-out control is provided, which mitigates the risk, but training-by-default for these tiers plus mandatory Feedback use makes this a moderate concern.
Data Retention & Deletion
The Privacy Policy provides an unusually detailed, itemised retention schedule covering conversations, API data (30 rolling days for abuse monitoring unless zero data retention is active), fine-tuning data, and legally mandated periods. Users can delete their account and conversations at any time via account controls, and a zero-data-retention option exists for certain APIs.
Third-Party Data Sharing
Sharing is limited to need-to-know recipients (team members, financial institutions, regulators, legal/professional services) and vetted sub-processors bound by data protection agreements, with a Trust Center sub-processor list referenced. The policy affirmatively states no sale, sharing (in the statutory sense) or targeted advertising has occurred in the preceding 12 months.
Opt-Out Rights
The policy provides concrete opt-out mechanisms: a user control to object to use of Input/Output for model training, controls to turn off the Memory feature, and the ability to opt out of IP-based personalization. Marketing communications are consent-based and withdrawable.
Compliance & Certifications
The documents demonstrate clear GDPR alignment (French controller, CNIL, SCCs, Article 46 safeguards, lawful bases) and address US state privacy laws (CCPA/CPRA and multiple other states). However, no specific security/AI attestation (SOC 2, ISO 27001, ISO 42001) is named in the supplied text — the policy references 'our certifications' and a Trust Center without naming any framework, so those remain unverifiable here.
Model Explainability & Auditability
The policy states Mistral does not engage in profiling or automated decision-making and references a Usage Policy commitment to transparency, and the Partner-Served terms include watermarking/traceability for weight access. However, there is no substantive commitment to enterprise model auditing or explainability of model behavior in the consumer documents.
Security Practices & Breach History
A Trust Center is referenced and the policy mentions security audits of sub-processors, watermarking of model weights, and a security-incident notification obligation for weight holders. However, the supplied documents disclose no specifics on encryption at rest/in transit, penetration testing, bug bounty, or breach history, and reference the vendor's own 'certifications' without naming them.
Enterprise vs. Consumer Risk Delta
The consumer terms reveal a material tier difference within the consumer space: free, Vibe Pro and Vibe Student data is used for training by default (opt-out available), while other paid usage is not trained on except via Feedback/moderation. The Partner-Served terms confirm that data used via cloud partners/own infrastructure is never used for training, indicating a favourable delta for infrastructure-served/enterprise deployments.
Human Review of User Inputs
Mistral reserves the right to monitor use through automated means and to review content flagged by moderation, and staff may access Input/Output for customer support, debugging and abuse enforcement. The policy states legally-retained data will not be accessed except for legal obligations or disputes, but human review for support and moderation is clearly contemplated.
Regulatory & Litigation Exposure
The documents disclose that Mistral may share data with regulators (CNIL), courts, and law enforcement, and will report illegal activity and CSAM to authorities. There are no disclosures of actual litigation or government data-request volumes, but cooperation with legal/governmental orders is expressly contemplated.
PII & SPI Data Inventory
Mistral collects a broad but disclosed range of PII (name, email, IP address, technical/usage data, billing information) with stated lawful bases and purpose limitation. Notably, sensitive personal data voluntarily included in prompts may be stored as a 'Memory' with explicit consent, and the US-user section states SPI is processed only as permitted by law — significant PII plus optional SPI handling with disclosure and controls places this at moderate risk.
Policy–Product Currency
The Privacy Policy is current in substance — it addresses AI/LLM training, third-party model interactions, MCP servers, integrations, fine-tuning and the Memory feature, matching the AI-first products (Vibe, Studio, Forge) visible in the product surface. However, no explicit effective or last-updated date appears anywhere in the supplied documents, which caps the rating at YELLOW and prevents a recency determination.
Cross-Document Consistency
Multiple documents were supplied (Privacy Policy, Partner-Served Terms, RoW Consumer Terms, Usage Policy). The training-use statements are consistent and complementary across them — the consumer terms describe training-by-default with opt-out for certain tiers, while the Partner-Served terms describe a distinct no-training/no-access model for infrastructure-served deployments. No genuine contradictions were identified across the documents.
You've read all 15 risk ratings for Mistral AI. Create a free account to see the exact policy wording behind each rating.