Mistral Chat (Le Chat)
Mistral AI · Chat assistant · FR · mistral.ai
services/mistral-chat-le-chat.yamlVendor data-handling terms
The policy lists training Mistral's language models as a purpose for processing Input and Output, subject to an opt-out available in the account's user preferences.
“Your Input and Output, subject to your opt-out. / You can opt-out of this processing at any time through your user preferences on your Mistral AI Account.”
The API retention clause below is the closest statement on business use; the policy does not separately state that API data is excluded from training.
“Except for specific APIs, we keep your Input and Output for the period necessary to generate the Output and then for thirty (30) rolling days to monitor abuse (unless zero data retention is activated).”
The consumer product is referred to as Vibe in the current policy text.
“we keep your Input and Output until you delete your account or until you delete the conversation from Vibe. / Except for specific APIs, we keep your Input and Output for the period necessary to generate the Output and then for thirty (30) rolling days to monitor abuse (unless zero data retention is activated).”
“We prioritize selecting providers within the European Union that strictly adhere to the GDPR. / However, in exceptional cases, we may opt for non-EU providers that meet our high standards of data security and Personal Data protection.”
Domains and endpoints
observed means seen in Unseen deployments; vendor-documented means listed by the vendor. Vendors do not publish complete lists.
| Host | Role | Source |
|---|---|---|
| chat.le.chat | app | observed |
| chat.mistral.ai | app | observed |
| le.chat | app | observed |
| mistralaichatupprodswe.blob.core.windows.net | upload | observed |
| mistralaifilesapiprodswe.blob.core.windows.net | upload | observed |
Assessment
Reasoning: Training on inputs is on unless the user opts out, which is the same exposure profile as other consumer assistants; the difference is an EU controller under GDPR, EU-first hosting, and a 30-day API retention window with zero data retention on request. For an EU deployer the open item is the opt-out state on personal accounts, not the location of the data.
Flags: GDPR Art. 21 objection mechanism relied on for training opt-out (consumer) · Assessed 2026-09-15. The assessment is Unseen's; the terms above are the vendor's.
Changelog
- 2026-09-15Documented. Training, retention, and transfer terms verified against the Mistral AI Privacy Policy.
- 2026-09-15Listed from the Unseen catalogue with observed domains.
Corrections
Pull request on GitHub, or the form below. Changes are reviewed and recorded in the changelog.