Did Mistral Remove Its No-Training Promise? What The New Policy Actually Says

July 29, 2026

Mistral removed a paid-API and Enterprise no-training sentence from its privacy policy, but other current terms still preserve defined exclusions. Here is the conflict.

Mistral removed an explicit paid-API and Enterprise no-training sentence from its privacy policy—but that does not prove Mistral started training on paid customer data. Its current commercial terms, help center, and product documentation still describe no-training protections for defined paid plans and API use. The real issue is a fresh conflict between documents that users should not have to reconcile themselves.

Updated July 28, 2026: This article reflects Mistral AI's privacy policy effective July 27, its current commercial terms, Data Processing Addendum, training and zero-data-retention help pages, privacy-control documentation, and an independently archived policy-change record.

Who This Article Is For

This article is for:

The short version is:

One protection disappeared from one public policy, but several current Mistral documents still state no-training rules. Treat this as a documentation conflict that needs clarification, not as proof of a secret training change.

What Is Confirmed

Mistral's Privacy Policy Changed Effective July 27

Mistral's current privacy policy identifies July 27, 2026 as its effective date.

The revision does more than replace the old Le Chat name with Vibe.

The policy now defines Input as data either:

Examples include prompts, content, and fine-tuning data.

That definition matters because an AI assistant can process more than the text typed into a chat box. Connected-drive documents, retrieved workspace content, uploaded files, agent instructions, and integration data may all enter the workflow.

The Policy Removed A Paid-API And Enterprise Training Exclusion

ConductAtlas change record CA-C-004012 compares archived versions and reports one removed sentence and seven modified sentences.

The removed language had explicitly said that Mistral did not use Input and Output to train its models when a user used:

That sentence is not present in the current privacy policy's model-training row.

The current row says Mistral may train models using:

That wording, read alone, is broader and less plan-specific than the previous policy.

Removing A Sentence Is Not The Same As Starting A New Practice

The independent change record explicitly stops short of claiming that Mistral now trains on paid API or Enterprise data. It describes the effect as operational ambiguity.

That distinction is essential.

A policy diff can prove:

A policy diff cannot prove:

The strongest accurate conclusion is that the privacy policy no longer contains the old explicit exclusion.

Mistral's Current Commercial Terms Still Limit Training

The contrary evidence is not buried in an old page. It appears in Mistral's current Commercial Terms of Service.

Section 4.1 says Mistral may use Customer Data and Outputs to provide, maintain, optimize, debug, assess, review, and correct its products, but says that purpose excludes model training.

Section 4.2 then says Mistral will not use Customer Data or Outputs to train its models except in defined cases, including:

Those are material exceptions. They also show why "paid" is not a sufficient privacy description by itself.

A paid Vibe plan, a paid Scale API organization, a Team workspace, an Enterprise contract, a Labs model, and a feedback submission can have different rules.

Mistral's Current Help Page Still Says Paid API Data Is Not Used For Training

Mistral's current model-training help page gives plan-specific answers:

The same help page says Feedback is different. A thumbs-up, thumbs-down, or accompanying comment can authorize Mistral to use the rating and associated Input and Output to improve model behavior.

That exception deserves its own decision. A general training setting and a voluntary feedback submission are not necessarily the same data path.

Mistral's Product Documentation Also Preserves No-Training Statements

Mistral's current privacy and data-controls documentation says:

The same page exposes controls for:

This is why the current record cannot support a headline saying Mistral definitely began training on paid customer data.

The Current Mistral Documents Do Not Say Exactly The Same Thing

Document or surface What it currently says Important limit
Privacy policy Input and Output may be used for training, subject to opt-out No longer includes the old paid-API/Enterprise exclusion sentence
Commercial terms Customer Data and Output are excluded from training except for listed cases Feedback, moderation, Labs Models, Order Forms, and some non-opted-out plans are exceptions
Training help page Team, Enterprise, and Scale-plan Input/Output are not used for training Vibe Free, Pro, Education, Studio Free, and Feedback have different rules
Privacy-controls docs API data and connector data are not used for training; paid Vibe plans are protected by default Admin choices and Labs Models can change the path
Data Processing Addendum Training may occur according to the privacy policy unless the customer has opted out Feedback and associated Input/Output can be handled separately
Zero-data-retention help Approved Scale organizations can use ZDR for supported stateless endpoints Vibe, agents, conversations, files, libraries, batch jobs, and stateful APIs are excluded

The table reveals the real story: "Mistral privacy" is not one rule. It is a stack of plan, product, endpoint, feature, control, and contract decisions.

What Is Still Unclear

Why Did Mistral Remove The Sentence?

Mistral's public revision does not explain whether the deletion was:

No dedicated Mistral announcement explaining that sentence removal was found during this review.

Which Document Controls For A Specific Customer?

The privacy policy says it does not apply in the same way when a business uses Mistral products to process personal data in its business activities; in that situation, the customer may be the controller and Mistral the processor.

A commercial customer may also have:

The correct answer for one customer can therefore differ from the general public policy.

This article is not legal advice. The operational lesson is simpler: identify the documents attached to the actual account and product, not the document that ranks highest in search.

Does The New Input Definition Change Connector Training?

The privacy policy now treats data accessed through connected integrations as Input.

Mistral's product documentation separately says connector data is fetched on demand, is not stored permanently, and is not used for training.

Those statements can coexist if the broader Input definition governs collection and processing while a narrower product rule limits training. But the public documents do not explain that relationship in one place.

Users still need to know:

Did Any Backend Training Practice Change On July 27?

The available sources do not answer that.

There is no public evidence in this review that Mistral:

There is also no public statement from Mistral saying the sentence removal was meaningless.

The unknown should remain visible until Mistral reconciles the documents or gives a direct explanation.

Training, Retention, And Zero Data Retention Are Different Questions

Mistral's current privacy policy says:

Mistral's ZDR help page says zero data retention is available only for approved Scale-plan organizations and supported stateless endpoints.

It explicitly excludes:

This creates three separate questions:

  1. Training: Can the content be used to improve a model?
  2. Retention: How long can the content or a derived record remain?
  3. State: Does the product need to store the content to provide history, files, memory, an agent, or another persistent feature?

Turning training off does not necessarily delete retained data. Activating ZDR for stateless chat completions does not make an Agents API or Files API request stateless.

A Seven-Part Audit For Mistral Users

1. Identify The Exact Product

Write down whether the data flows through:

The model name alone does not identify the data path.

2. Identify The Exact Plan And Organization

Check whether the account is:

Then confirm which organization and workspace own the request. A personal Vibe account is not interchangeable with an employer's Enterprise workspace.

3. Capture The Current Privacy Controls

Record:

Do not rely on a remembered default. Defaults, administrators, and product updates can change.

4. Check The Contract Stack

Review the privacy policy together with the Commercial Terms, Additional Product Terms, DPA, Order Form, and any partner-hosting terms that apply.

If the documents conflict, ask the vendor to identify the controlling provision in writing.

5. Treat Feedback As A Separate Data Submission

Before rating a response, ask whether the feedback package may include:

If the documentation does not answer the payload question, avoid submitting sensitive feedback.

The same principle applies across providers. See what an AI feedback button may share and whether feedback can override a training opt-out.

6. Minimize Connector And File Scope

Grant access only to the source needed for the task. Prefer:

Data minimization does not replace a contract, but it reduces the amount of data exposed when a control is misunderstood.

7. Recheck After Material Policy Changes

Save:

A privacy review should be reproducible. "The website used to say no training" is weaker evidence than a dated record tied to the actual service.

What This Does Not Prove

Mistral's policy revision does not prove that:

The revision also does not prove that nothing changed. Removing a specific public protection creates a legitimate question, especially when the replacement policy uses broad Input and Output language.

The honest position is between those extremes: a protection disappeared from the privacy policy, other Mistral documents still preserve defined exclusions, and Mistral should reconcile the conflict.

Where OpenVeil Fits

OpenVeil is not a Mistral reseller, a contract-audit service, or proof that another provider mishandled data.

OpenVeil is a paid, privacy-focused AI chat web app with:

OpenVeil does not use prompts, uploaded files, images, audio, selected local history context, or AI outputs to train foundation models.

Its boundary still matters: active requests may be processed by OpenVeil and necessary AI, search, upload-processing, hosting, routing, security, billing, and infrastructure providers. OpenVeil is not fully offline, anonymous, zero-log, HIPAA compliant, or a guarantee that data never leaves the device.

If the Mistral change made you review AI privacy claims more carefully, compare:

Then read the OpenVeil privacy policy before deciding whether its hosted-processing and browser-local-history model fits your work.

FAQ

Did Mistral Remove Its No-Training Promise?

Mistral removed a sentence from its privacy policy that explicitly excluded Le Chat Enterprise and paid API Input and Output from model training. However, its current commercial terms, help center, and product documentation still state no-training protections for defined paid plans and API use. The removal creates a documentation conflict, not proof that all paid data is now trained on.

Does Mistral Train On Paid API Data?

Mistral's current training help page says Scale-plan Input and Output are not used for training, and its privacy-controls documentation says API data is not used for model training. Its commercial terms contain exceptions for Feedback, moderation or reported data, Labs Models, applicable Order Forms, and some plan or opt-out combinations.

Does Mistral Train On Enterprise Conversations?

Mistral's current help page says Vibe Team and Enterprise Input and Output are not used for training. The privacy policy no longer contains its previous explicit Enterprise carve-out, so Enterprise customers should verify the commercial terms, DPA, Order Form, and live admin settings that govern their accounts.

Does Mistral Use Connector Data For Training?

Mistral's current product documentation says connector data is fetched on demand, is not stored permanently, and is not used for training. Its revised privacy policy now includes data accessed through connected integrations in the definition of Input. The public documents do not clearly explain that relationship in one place.

Are Mistral Vibe Pro Chats Used For Training?

Mistral's current help page says Vibe Pro Input and Output are used for training by default unless the user opts out. Its privacy-controls documentation says Vibe Pro conversations are not used for training by default. Those two current statements appear inconsistent, so Pro users should inspect the live control and request clarification before using sensitive data.

Is Mistral Zero Data Retention Available For Vibe?

No. Mistral's current ZDR guide says ZDR is not available for Vibe Work or Chat. It is limited to approved Scale-plan organizations using supported stateless API endpoints.

Does Mistral ZDR Cover Agents And Files?

No. Mistral's current guide excludes agents, conversations, libraries, batch jobs, the Files API, and other stateful products from ZDR.

Does Turning Off Training Delete Mistral Chats?

Not automatically. Training control and retention are separate. Mistral says Vibe chats remain until a conversation or account is deleted, while many API requests may be retained for 30 rolling days unless approved ZDR applies.

Can Mistral Use Feedback For Training?

Yes, Mistral's current help and commercial documentation describe Feedback as a separate exception that can include the rating and associated Input and Output. Avoid submitting sensitive feedback unless you understand the payload and purpose.

Is A Self-Hosted Mistral Model Affected By This Privacy Policy?

Not automatically. A genuinely self-hosted open-weight model can follow a different data path from Mistral's hosted Vibe and API products. You must still audit the surrounding app, telemetry, tools, search, connectors, logs, storage, and fallback providers before calling the full workflow local or private.

Is OpenVeil A Fully Offline Alternative To Mistral?

No. OpenVeil is a hosted, privacy-focused AI chat service with browser-local history and no normal server-side chat-history record for private sessions. Active requests still require processing by OpenVeil and necessary providers.

The Bottom Line

Mistral removed a clear paid-API and Enterprise no-training sentence from its July 27 privacy policy. That is real and worth scrutiny.

It is equally real that Mistral's current commercial terms, help pages, and product documentation still preserve no-training statements for defined API, Team, Enterprise, connector, and library use—along with important exceptions.

Do not flatten that conflict into "nothing changed" or "Mistral now trains on every paid prompt."

The practical response is to identify the exact product, plan, endpoint, control, and contract; minimize connected data; separate training from retention; and ask Mistral to reconcile its public documents.

If you want a paid privacy-focused AI chat workspace with browser-local history, review OpenVeil and its privacy policy against the same questions before you trust it with sensitive work.

Sources

When privacy, account control, uploads, and search matter, OpenVeil gives you a private AI workspace designed for that job.