← All pages

1. What the document is: Mistral AI's consumer-facing Privacy Policy for Le Chat and Mistral AI Studio — covers data collection, an explicit AI-training purpose table, retention periods, international transfer safeguards, and (added 2025-12-31) a U.S.-state-law disclosure section.

What this wiki found — complete, every page

AI trainingRoyalty-freeSublicensablePerpetual / irrevocableTransferableDerivative works

Presence facts, not verdicts — each flagged term links to its definition and the exact clause on this page. Absence of a badge means the term isn't currently flagged here, not that the page is risk-free.

Le Chat – Privacy Policy

Dataset: GenGA (Generative AI Governance Archive) — 11 AI services, 2025–present

GenGA (Generative AI Governance Archive) is this wiki’s Generative-AI dataset: raw policy snapshots captured by the Open Terms Archive genai-eu project across 11 GenAI providers (ChatGPT, Claude.ai, DeepSeek, Google Generative AI Services, Le Chat, Llama API, Meta AI, Microsoft Copilot, Perplexity, Qwen Chat, xAI). Unlike PGAv2, GenGA has no pre-tagged risk scores — all risk scoring and keyword tagging on these pages is LLM-assigned by direct reading, spanning 2025–present.

Note: This page contains documented policy clauses. Risk assessment is qualitative and context-dependent. For analysis of patterns across platforms, see:

Source: sources/GenGA/Le Chat/Privacy Policy/ (raw Markdown captures, Open Terms Archive genai-eu dataset — no pre-tagged JSONL exists for this source) Last updated: 2026-04-08

Note on methodology: No pre-computed risk_score/keyword fields exist for this source. Keyword tags and clause analysis on this page are LLM-assigned, using the same rubric/vocabulary as the PGAv2 pages plus new GenAI-specific tags (input license, train AI/models, gdpr, feedback). Treat as first-pass analysis, not externally verified ground truth. This wiki’s risk-scoring system was retired project-wide on 2026-06-21 (see methodology.md §4) — no page, GenGA included, computes or displays a numeric risk score.

Skipped capture: 2025-12-15T11-34-51Z.md (31 bytes, body reads only “Redirecting to legal.mistral.ai”) is a failed scrape, not a real policy version — skipped and excluded from the dates below.

Data-quality note: Captures from 2025-12-15 onward contain the entire policy text twice within the same file (the same scraper/page-rendering artifact found elsewhere in Le Chat’s documents) — quotes below are from the first occurrence only.


Overview

1. What the document is: Mistral AI’s consumer-facing Privacy Policy for Le Chat and Mistral AI Studio — covers data collection, an explicit AI-training purpose table, retention periods, international transfer safeguards, and (added 2025-12-31) a U.S.-state-law disclosure section.

2. Input rights: Same opt-out-by-default structure documented in Le Chat’s Commercial Terms: Input/Output is training-eligible “subject to your opt-out,” explicitly excluding Le Chat Enterprise and paid API users. Genuine, confirmed cross-document finding: “Le Chat Team” was excluded from training by default through 2026-04-02, then removed from the exclusion list on 2026-04-08 — meaning Le Chat Team users became training-eligible-by-default unless individually opted out. This matches the same broadening trend documented in Le Chat’s Commercial Terms, where “Le Chat Teams” was added to the default-training tier list on the same date.

3. Output restrictions: Not addressed in this document (governed by the separate Commercial Terms/Terms of Service).

4. Non-explicit predatory clauses: A “Memory” feature stores Input (including sensitive data, with “explicit consent” claimed) to personalize responses. A “Training Datasets” disclosure (added 2025-12-31) acknowledges Mistral uses third-party-provided datasets, “non-public third-party databases,” and synthetic data for training, with collection “ongoing” since 2023.

5. Regulatory references: GDPR explicitly cited — Article 46 SCC safeguards for non-EU data transfers, French CNIL as the supervisory authority, and (added 2026-04-02) a formal Data Protection Officer (DPO) contact channel, a concrete GDPR Article 37 compliance signal not found explicitly in most other providers’ Privacy Policies in this dataset. The 2025-12-31 addition also adds CCPA/U.S.-state-law disclosures (California, Colorado, Connecticut, Delaware, Iowa, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Texas, Utah, Virginia).

6. Regional variation: EU-centric design (GDPR/CNIL/DPO) with a bolted-on U.S.-state-law section for American users — the only Le Chat document in this dataset with explicit multi-jurisdiction (EU + 13 US states) disclosure.

7. Key risk to users: The Le Chat Team default-training reversal is the standout risk — a tier marketed for business/team use lost its no-training protection without any change to the underlying product description, only a quiet table-row edit.

Flagged Keywords & Risks (LLM-assigned)

Regulatory & Research Context

Pandit et al. (2026), who directly studied Mistral/Le Chat’s privacy terms, found that “all terms mentioned that inputs and outputs would also be used for other purposes beyond” the immediate service, including training on “non-public third-party databases” and synthetic data as disclosed in this page’s Training Datasets section. Applying Davidson et al.’s (2026) regulatory-gray-area framework by analogy (Mistral was not among the providers they directly studied), the quiet removal of “Le Chat Team” from the no-default-training exclusion list on 2026-04-08 — converting a previously-protected business tier into a training-eligible-by-default one with no accompanying product change — is precisely the kind of unannounced narrowing of user protection their framework treats as a source of legitimate-use uncertainty.


Changes Summary

DateWhat changed
2025-11-11Baseline version (“Effective 27 May 2025”) — already contains the full training-purpose table, Memory feature, retention periods, and GDPR Article 46/CNIL references.
(2025-12-15 11:34, skipped)Failed capture — page redirected to legal.mistral.ai, no content retrieved.
2025-12-15 23:34Re-issued under “Effective: November 28, 2025” with URL/product-name updates (“La Plateforme” → “Mistral AI Studio”); no substantive change to flagged clauses.
2025-12-31Genuine additions: new “Training Datasets” bullet (third-party datasets, non-public databases, synthetic data); new full “Additional Disclosures for U.S. Users” section (CCPA/13-state rights, training-data sourcing details, training “began in 2023, is ongoing”).
2026-04-02Genuine addition: formal Data Protection Officer (DPO) contact channel added, separate from the general Privacy Team contact.
2026-04-08Genuine, predatory-direction change: “Le Chat Team” removed from the no-default-training exclusion list — Team-tier users became training-eligible-by-default unless individually opted out.

Version History

2025-11-11

Clause: train AI/models

To train our artificial intelligence models (large language models) to answer questions, generate text, translate, summarize and correct text, classify text, analyze feelings, etc. according to context, Inputs (e-mails, letters, reports, computer code, etc.) and Outputs. | Personal data included in the data publicly available on the Internet, despite our efforts to filter out such personal data; Your Input and Output, subject to your opt-out. Please note that we do not use your Input and Output to train our artificial intelligence models when you use Le Chat Team, Le Chat Enterprise or the paid version of our APIs. […] Your Feedback.

Clause: gdpr

We take the necessary steps to ensure that all contracts with service providers who process personal data outside the European Union have adequate safeguards in compliance with Article 46 of the GDPR. Additionally, we attach the most recent version of the European Commission’s Standard Contractual Clauses to all such contracts.

Clause: feedback

“Feedback”, any information you provide when you rate an Output, such as “thumbs up” or “thumbs down”, and the associated Input and Output.


2025-12-15

All flagged clauses unchanged from 2025-11-11 (re-issued under new URLs/product names with no substantive change).


2025-12-31

train AI/models (Le Chat Team still excluded)/gdpr/feedback unchanged from 2025-11-11.

Clause: train AI/models (new — Training Datasets disclosure)

Training Datasets. In some cases, we access datasets provided by third parties for our model training purposes. These datasets may include personal data (even if such third parties and Mistral AI use good practices to filter out such personal data), proprietary data, or public data.

Clause: train AI/models (new — U.S. disclosure detail)

Training Information. We use and have used a mix of proprietary and third-party data to train the artificial intelligence models used in the Mistral AI Products for improved performance, which can include information in a variety of formats (such as text or images) from publicly available datasets and internet sources, non-public third-party databases, your use of our products (to the extent permitted by our applicable terms), internally generated data, curated datasets, and synthetic data. Such collection and training began in 2023, is ongoing, and is used to improve our artificial intelligence models. Our training datasets may include aggregated consumer information.


2026-04-02

train AI/models (Le Chat Team still excluded)/feedback unchanged from 2025-11-11.

Clause: gdpr (new — DPO contact)

How to contact our Data Protection Officer (DPO): By using the “Privacy Requests” contact form available here. By sending us a letter at Mistral AI, Attn: DPO, Mistral AI, 15 rue des Halles, 75001 Paris, France.


2026-04-08

gdpr/feedback unchanged from 2026-04-02.

Clause: train AI/models (Le Chat Team exclusion removed)

To train our artificial intelligence models (large language models) […] Your Input and Output, subject to your opt-out. Please note that we do not use your Input and Output to train our artificial intelligence models when you use Le Chat Enterprise or the paid version of our APIs. […] Your Feedback.