Context: After careful research our organization preferred a European partner with good central privacy controls. We landed on Mistral, after being disappointed that the Pro tier was opt-in to training on prompts by default we switched up to the Team tier which provides an organization dashboard with some relevant settings. As we did that Mistral changed these options and the Team tier was now also opt-in by default and at the same time seemed to have lost the ability to centrally disable training on prompts for your entire organization. This even caused some of our (testing) prompts to be used for training (which Mistral removed after we expressed our disappointment).
For some time these pages conflicted with what our users reported (they said that in contrast to what I stated to our management they found they were opted into training on prompts by default as per their own privacy page). Mistral just now corrected their docs. I'm not sure how long the conflicting situation has lasted, but at least for several days.
For contrast: Claude disables training on prompts for organizations starting from the 18 euro tier [0]. As a European I'm disappointed.
> and at the same time seemed to have lost the ability to centrally disable training on prompts for your entire organization
There is a toggle on https://admin.mistral.ai that allows you to disable training for both Vibe and Console/API for your entire organisation. And I'm not on the enterprise plan. I've disabled training the first time I created an account, and it has remained that way.
You story is also very confusing due to the wording around "opt-in by default" and "disappointed [about] opt-in to training" (most people would be disappointed about an opt-out) and probably conveys the wrong message to most people.
I don't have that toggle (but could indeed have sworn I saw it earlier).
Sorry, I have always thought that "opting in" is, "opting for the presented option" and opting out is "opting out of it", so opting out [of sharing prompts for training] is choosing to not share, but apparently I was wrong my whole life. I'm not a native speaker, and I think most people here (in my country) would interpret this the way I do? Weird but TIL.
FWIW I don’t find what you wrote confusing, but I do think it is following a sort of… bad convention that some companies have been pushing.
Opt-in and opt-out describe the nature of the choice that you make. “Opt” means to choose (apparently it is a French word we stole). Opt-in means you have to proactively choose to be in. Opt-out means you have to proactively choose to be out. “Opt-in by default” is an overly verbose way of saying “opt-out.”
In either case it describes the choice that you need to proactively make to override the default behavior.
Edit: I should also say that it is a “known point of contention” where pro-privacy people have been pushing back on this phrasing. So, you have probably accidentally stumbled into an ongoing discussion, which is why some of the comments might be unexpectedly prickly.
Allow the use of your API calls to train Mistral’s AI models.
Enable Labs models
So indeed, no "Allow the use of your interactions with Vibe to train Mistral’s AI models". I only see that setting here: https://chat.mistral.ai/chat?profile_dialog=privacy
And I have to ask every user in my org to go and turn it off.
If you opt in it means that by default you're not in and you chose that option. So if you're now included in training by default, then it's an opt-out feature as in you can opt out of it.
“disappointed that the Pro tier was opted-in to training on prompts by default” [and required manually opting out]
“the Team tier was now also opted-in by default” [and required manually opting out]
In context of each sentence and the larger comment, read smoothly here.
Also - have seen more than one lively discussion on these phrases, since defaults can stick 95% of the time and Big Tech has done their best to be abusive about what they automatically enable for users by default for some time.
Yes, individual indeed (used to different but changed about a year ago, see [0] among others].
For the Team and Enterprise plans de default is "not sharing prompts for training" (which I mistakenly referred to as opted out of sharing prompts for training.) [1]
Because they have no incentive as a company to do that?
But do have a strong incentive to learn from user input.
(Most cutting edge features are developed private - very valuable to get that into your tool)
And getting the data is not hard, they already have it.
Risky is indeed a bit making use of that data, as that requires at least some humans (as potential whistleblowers). But you don't even have to tell them, where the data came from.
Whether they do it? No idea, I assume not, but I see a risk.
You are "opting in to sharing your prompts for training", by default in this case. My slider says: "Allow the use of your interactions with Vibe to train Mistral's AI models.", it is on by default for everyone on the Team plan, the admin can't centrally turn it off anymore, and any user can toggle it when they want to. This all changed last week.
I know I'm naive but I expect that when I pay, this stuff is simply off, so I was already surprised by the Pro plan. But I did look out for it there, because Anthropic made this switch some time ago.
> You are "opting in to sharing your prompts for training", by default in this case.
The English term for that is "opt out" not "opt in." To opt is to choose. If something is on by default, you have not opted in. You were forced in, and turning it off means you must opt out. (I.e., choose to be out.)
normally I wouldn't care about a mistake like this, except that opt in/out are very important concepts in software development and hacker culture. And it reversed the meaning of the original comment in a highly confusing, relevant way.
as another non-native speaker, i think that while the person you're answering to didn't use the default way of expressing this in the english-speaking world, i did understand what they meant, i think they do know what opting means and i think the reasoning is this:
when they say data collection is "opt in" by default they mean that by choosing to use a product, you are opting into your data being collected (at the same time).
on the other hand, native speakers saying something is "opt out" describes the options or toggles one has available in the default case - when something is toggled "true", you (only) have the choice to toggle it of.
so english speakers talk about the controls one has to CHANGE the status quo.
They said "opt in to training on prompts by default," which is coherent English and perfectly fine. The phrases "opt in" and "opt out" will always be contextual based on what is being opted, so it really falls to the reader to pay attention to that context. Please don't give English language advice as though you are an authority; there is not a rule of the English language that would make their usage unacceptable.
The page title is "Can I opt out of my input or output data being used for training".
Right at the top of the page it says "In certain cases, your input and output data (such as conversations, documents, and other user-provided content) may be included in Mistral’s model training programs. You retain full control over this processing and have the right to opt out of these programs at any time."
"Of course we'll randomly turn that option off for you aka FB style and hope you don't notice. There is zero legal liability for us doing so, so why wouldn't we".
Agreed. I read the title as they would start using my data for training and I couldn't opt-out. After looking at the page and checking my app (I have Pro subscription) it seems like I can opt-out and my initial opt-out when I subscribed was preserved.
When I started my search for an AI "partner" the Mistral TEAM plan had "use my prompts for training" turned off by default, as per their docs in multiple places. I could have sworn I saw a organization switch in my dashboard for this setting org wide, but am not sure.
I start the subscription, users report it is "on" by default, I ask support what's up, they say "sorry, docs should have been updated earlier but they are now". And they give me a lot of credits.
I just want to warn people, the Team sub just changed, docs were update too late, there was very little press about this (in my view) very important change. Actually, it is so important that I would not advice Mistral to our management if they'd use our prompts for training, so I take a TEAM sub so this is disabled for sure, or I can disable this org wide. But I can't anymore, now I have to ask each user/seat to disable sharing, and hope they do, I have no way to check. Way to inspire confidence. And their response: "You can still do this with the Enterprise subscription".
We flamed Anthropic for their switcheroo with their personal Pro plan a year ago [0], now Mistral does it with their business focused Team plan, so they deserve some fire imo.
"No model training on your content by default" [0]
It's not the default on any Team plans and didn't used to be at Mistral (until last week or so). The team plan has a central admin role and page, and "seats".
And if it was the default, then I'd still expect a big button to turn it off for all seats, and not have to ask all user separately. But this changed over night and that button is not there. Although I expect it used to be, because some people here report that they have it.
I'd be interested in some legal/GDPR takes on PII handling in prompts. If someone enters PII into a prompt, and Mistral retains it for training, is it sufficient for them to say "don't enter PII into prompts?"
Of course with Claude and so on this bothers me too, but it doesn't seem like there's any real recourse under US law. But I would hope that "oh you shouldn't enter PII" isn't going to cut it under European law, that if I say "don't store my prompts, they include PII I don't want you storing" should be sufficient here under the GDPR and Mistral shouldn't be able to just store it anyway.
How many times with large companies have you found that they removed the old opt-out value and put a new one in that is enabled by default because of course it's opt-out?
Opt-out doesn't mean dick when the regulatory environment allows them to do things like the above without any recourse. Of course you can go to any other company that follows the exact same rules if you'd like.
Defaults matter. The expectation for an organization tier plan is not that you have to go and ask each user in your org to please turn off "Allow the use of your interactions with Vibe to train Mistral's AI models" before starting your work.
Maybe they realized that they were falling behind too much? To me it seems like user-feedback on bad descisions by the AI once it's trained to a basic level is among the most important signals in tuning the model to perform better.
That's what I believe. Once you have scanned every passive source available, using the user conversations to e.g. find common paths to a solution and shortcut them would seem natural.
Paths and shortcuts isn't the most important part here I think, rather negative signals about unfitting choices is more important, do we use algorithm/library/etc XYZ in this situation or not, the developers using it would provide the context suitability of options on a more finegrained level than resulting (semi-)public artifacts provide.
You must have not been keeping up with the times :)
Their big play this year was to write a "whitepaper" on the future state of EU economy, which is something that they'd like to hand of to EU leaders and part of that proposal was some kind of mandatory 10% sovereign AI spend, or some other nonsense like that.
They are, at least, trying to make big enterprise (with tailored models, custom integration) and government policy plays.
That just goes to show you how ineffective they are as well at making AI click as a usecase.
And when they don't get ahead by their own terms they copy what they see ongoing with US AI labs. Le Chat, and Vibe.
To have at least a choice of using a European trained model. Downloadable weights is not open source. Mistral is able to respond to any regulatory queries about training data and concerns.
To be honest, I have a hard time noticing differences with Claude (in Kiro) and Mistral Vibe, at least with what I use them for. They simply feel like talking to the exact same thing.
The OCR stuff is quite usable. Their models perform good at some very basic tasks, so I use them to diversify. But their current model lineup is really terrible.
EU companies can download GLM or Kimi-K3 and get way better performance, though? I don't see any case for using a Mistral model when much better open models exist.
Because not everyone has the infrastructure to run that with better performance? Anyway, Mistral serves GLM 5.2 through their global and European endpoints, so if you wanted to leverage their services and use a more powerful open model, that seems to be an option.
You can still easily disable "Allow the use of your interactions with Vibe to train Mistral's AI models." What's annoying is that they switched this to on by default on Team plans with no way to turn it off for your whole team/org, this week.
I'm really hoping Mistral will succeed with their open models, so I'm a bit biased, but I don't have any affiliation. This submit is a bit of well-meaning but confused scaremongering however.
Mistral has had, and continues to have, a toggle in the admin settings that permanently disables training on your data. The option has not been removed, and previous opt-outs are still honored. As far as I know, Mistral always trained on your data by default except for the enterprise plan, with the option to disable it on all plans, and with the option for organizations to make the choice for all your users.
Kagi Ultimate still uses mostly closed models by OpenAI / Anthropic, etc.
There is no toggle in my admin settings to disable this for the whole org (when on the Team plan). If it was there before they recently removed it.
"Mistral always trained on your data by default except for the enterprise plan" - This is not true, until last week all docs stated that the use of your interactions with Vibe to train Mistral's AI models was off by default on the Team plan. Now that is only still the case on the enterprise plan.
My best experience with Mistral has been with their expensive GLM-5.2 model. It's actually developed by Z.ai, but unlike Z.ai, the GLM-5.2 at Mistral can be used at a low price without training on your prompts - but only if you remember to hit the privacy toggle in their admin settings.
Planning code changes with GLM-5.2 using a Mistral Studio API key and implementing code changes using the Mistral Vibe API key has worked well for me. At my basic subscription tier, Vibe will share data with Mistral. It works for me because, when it comes to privacy, I care less about the actual code and more about the planning / high-level stuff.
> My best experience with Mistral has been with their expensive GLM-5.2 model. It's actually developed by Z.ai, but unlike Z.ai, the GLM-5.2 at Mistral can be used at a low price without training on your prompts - but only if you remember to hit the privacy toggle in their admin settings.
Same here, actually. I'm American but have had a Mistral sub to supplement local models. The Mistral models, IMO, are very hit or miss, and I was about to cancel my sub until I saw they added GLM.
Most commenters here clutching their pearls as if Claude and Gemini Pro didn't do it already. In the latter you (as a paying customer) can't even store the chat history unless you agree to their 'improvement of services'.
Do you have all your accounts paid for by the enterprise or you never check the settings?
> Most commenters here clutching their pearls as if Claude and Gemini Pro didn't do it already.
That's not the point though. The problem is that in the minds of lots of people including here on HN or otherwise, a service based in the EU is de-facto "more" respectful of digital privacy.
You can read the comments on threads related to the EU tech where you will find people defending to the very end that privacy is better in the EU and that EU providers will never stoop as low as their US counterparts.
As always the truth is a lot murkier than that.
Yes, some services based in the EU are better in terms of privacy but it's not a given for all of them and it depends entirely on the service. Unfortunately such a nuanced take is not wildly popular in the tech world in this day and age where every US company is labelled as an evil data hungry entity and EU companies are portrayed as saints in this regard.
That's where the first problem lies.
The second problem is that for years now, people have been singing the praises of Mistral as a privacy friendly alternative the the US juggernauts because Mistral's headquarters is located in the EU and unfortunately today it seems some people are waking up to the fact that Mistral is doing the same thing than its US counterparts and they are disappointed which is understandable.
Who is to blame for this dichotomy? Is it Mistral who leaned too much on this marketing angle (the European Chatgpt without the invasive tracking/ better privacy settings) or is it the users who failed to realize that EU or not, Mistral wasn't going to pass on the opportunity to improve its models this way?
I had the option, and had it disable everywhere, manually. The only one I didn't use, at all, is Anthropics service because of iffy Dario aura and their terms of service. Where is training in user data enforced and not possible to opt out?
Taking away the ability to centrally enforce an opt-out across an organization is a massive red flag.
You can't reasonably expect every individual employee on a Team plan to remember to dig into their personal settings and flip a privacy toggle. For any company dealing with sensitive IP or GDPR-compliant data, this basically makes the Team tier unusable.
This isn't the case. There's a toggle on https://admin.mistral.ai that allows you to disable training for both Vibe and Console/API for your entire organization, I just checked.
For some time these pages conflicted with what our users reported (they said that in contrast to what I stated to our management they found they were opted into training on prompts by default as per their own privacy page). Mistral just now corrected their docs. I'm not sure how long the conflicting situation has lasted, but at least for several days.
For contrast: Claude disables training on prompts for organizations starting from the 18 euro tier [0]. As a European I'm disappointed.
[0] https://claude.com/pricing#team-&-enterprise
There is a toggle on https://admin.mistral.ai that allows you to disable training for both Vibe and Console/API for your entire organisation. And I'm not on the enterprise plan. I've disabled training the first time I created an account, and it has remained that way.
You story is also very confusing due to the wording around "opt-in by default" and "disappointed [about] opt-in to training" (most people would be disappointed about an opt-out) and probably conveys the wrong message to most people.
Sorry, I have always thought that "opting in" is, "opting for the presented option" and opting out is "opting out of it", so opting out [of sharing prompts for training] is choosing to not share, but apparently I was wrong my whole life. I'm not a native speaker, and I think most people here (in my country) would interpret this the way I do? Weird but TIL.
Opt-in and opt-out describe the nature of the choice that you make. “Opt” means to choose (apparently it is a French word we stole). Opt-in means you have to proactively choose to be in. Opt-out means you have to proactively choose to be out. “Opt-in by default” is an overly verbose way of saying “opt-out.”
In either case it describes the choice that you need to proactively make to override the default behavior.
Edit: I should also say that it is a “known point of contention” where pro-privacy people have been pushing back on this phrasing. So, you have probably accidentally stumbled into an ongoing discussion, which is why some of the comments might be unexpectedly prickly.
You don't see "Allow the use of your interactions with Vibe to train Mistral’s AI models" at https://admin.mistral.ai/vibe/privacy ?
And "Allow the use of your API calls to train Mistral’s AI models" at https://admin.mistral.ai/plateforme/privacy ?
at https://admin.mistral.ai/vibe/privacy:
Allow public sharing of chats content
Allow user feedback on model responses
Chat Retention Policy
At https://admin.mistral.ai/plateforme/privacy I see
Allow the use of your API calls to train Mistral’s AI models.
Enable Labs models
So indeed, no "Allow the use of your interactions with Vibe to train Mistral’s AI models". I only see that setting here: https://chat.mistral.ai/chat?profile_dialog=privacy And I have to ask every user in my org to go and turn it off.
“disappointed that the Pro tier was opted-in to training on prompts by default” [and required manually opting out]
“the Team tier was now also opted-in by default” [and required manually opting out]
In context of each sentence and the larger comment, read smoothly here.
Also - have seen more than one lively discussion on these phrases, since defaults can stick 95% of the time and Big Tech has done their best to be abusive about what they automatically enable for users by default for some time.
In theory also for individuals?
At least I have that toggle to deactivate that. But how would I ever know if they actually respect that?
The only company you could think of trusting is one where an external , independent auditor is doing its work.
Your comment is perplexing. No company on earth meets your requirement. What are you expected to do? Move to a hut in the woods?
For the Team and Enterprise plans de default is "not sharing prompts for training" (which I mistakenly referred to as opted out of sharing prompts for training.) [1]
[0] https://news.ycombinator.com/item?id=45076274
[1] https://claude.com/pricing#team-&-enterprise
And getting the data is not hard, they already have it. Risky is indeed a bit making use of that data, as that requires at least some humans (as potential whistleblowers). But you don't even have to tell them, where the data came from.
Whether they do it? No idea, I assume not, but I see a risk.
I know I'm naive but I expect that when I pay, this stuff is simply off, so I was already surprised by the Pro plan. But I did look out for it there, because Anthropic made this switch some time ago.
I understand what you're saying here, but maybe "turned on by default" is less confusing for everyone.
The English term for that is "opt out" not "opt in." To opt is to choose. If something is on by default, you have not opted in. You were forced in, and turning it off means you must opt out. (I.e., choose to be out.)
normally I wouldn't care about a mistake like this, except that opt in/out are very important concepts in software development and hacker culture. And it reversed the meaning of the original comment in a highly confusing, relevant way.
That's called opt-out.
The page title is "Can I opt out of my input or output data being used for training".
Right at the top of the page it says "In certain cases, your input and output data (such as conversations, documents, and other user-provided content) may be included in Mistral’s model training programs. You retain full control over this processing and have the right to opt out of these programs at any time."
....
"Of course we'll randomly turn that option off for you aka FB style and hope you don't notice. There is zero legal liability for us doing so, so why wouldn't we".
I start the subscription, users report it is "on" by default, I ask support what's up, they say "sorry, docs should have been updated earlier but they are now". And they give me a lot of credits.
I just want to warn people, the Team sub just changed, docs were update too late, there was very little press about this (in my view) very important change. Actually, it is so important that I would not advice Mistral to our management if they'd use our prompts for training, so I take a TEAM sub so this is disabled for sure, or I can disable this org wide. But I can't anymore, now I have to ask each user/seat to disable sharing, and hope they do, I have no way to check. Way to inspire confidence. And their response: "You can still do this with the Enterprise subscription".
We flamed Anthropic for their switcheroo with their personal Pro plan a year ago [0], now Mistral does it with their business focused Team plan, so they deserve some fire imo.
[0] https://news.ycombinator.com/item?id=45076274
It's not the default on any Team plans and didn't used to be at Mistral (until last week or so). The team plan has a central admin role and page, and "seats".
And if it was the default, then I'd still expect a big button to turn it off for all seats, and not have to ask all user separately. But this changed over night and that button is not there. Although I expect it used to be, because some people here report that they have it.
https://claude.com/pricing#team-&-enterprise
Of course with Claude and so on this bothers me too, but it doesn't seem like there's any real recourse under US law. But I would hope that "oh you shouldn't enter PII" isn't going to cut it under European law, that if I say "don't store my prompts, they include PII I don't want you storing" should be sufficient here under the GDPR and Mistral shouldn't be able to just store it anyway.
Opt-out doesn't mean dick when the regulatory environment allows them to do things like the above without any recourse. Of course you can go to any other company that follows the exact same rules if you'd like.
All the other businesses have been bought up by VC, going to rental models, and looking for new and interesting ways to screw you over too.
Service: Vibe Plan: Non-Enterprise Default: Opted in Opt-out possible? Yes
Service: Vibe Plan: Enterprise Default: Opted out Opt-out possible? Yes (admin-managed)
Service: Mistral Studio/API Plan: Not specified Default: Not stated, I assume opted in Opt-out possible? Yes
Their big play this year was to write a "whitepaper" on the future state of EU economy, which is something that they'd like to hand of to EU leaders and part of that proposal was some kind of mandatory 10% sovereign AI spend, or some other nonsense like that.
They are, at least, trying to make big enterprise (with tailored models, custom integration) and government policy plays.
That just goes to show you how ineffective they are as well at making AI click as a usecase.
And when they don't get ahead by their own terms they copy what they see ongoing with US AI labs. Le Chat, and Vibe.
This is them just making it very clear and disclosing as per European rules.
I think I will be using Kagi Ultimate for the inference UI, so the data is somewhat anonymized before being collected.
Mistral has had, and continues to have, a toggle in the admin settings that permanently disables training on your data. The option has not been removed, and previous opt-outs are still honored. As far as I know, Mistral always trained on your data by default except for the enterprise plan, with the option to disable it on all plans, and with the option for organizations to make the choice for all your users.
Kagi Ultimate still uses mostly closed models by OpenAI / Anthropic, etc.
"Mistral always trained on your data by default except for the enterprise plan" - This is not true, until last week all docs stated that the use of your interactions with Vibe to train Mistral's AI models was off by default on the Team plan. Now that is only still the case on the enterprise plan.
You can opt out in this one.
Planning code changes with GLM-5.2 using a Mistral Studio API key and implementing code changes using the Mistral Vibe API key has worked well for me. At my basic subscription tier, Vibe will share data with Mistral. It works for me because, when it comes to privacy, I care less about the actual code and more about the planning / high-level stuff.
Same here, actually. I'm American but have had a Mistral sub to supplement local models. The Mistral models, IMO, are very hit or miss, and I was about to cancel my sub until I saw they added GLM.
Using Claude, Mistral and the rest of them is not going to solve your issue with data collection.
That's not the point though. The problem is that in the minds of lots of people including here on HN or otherwise, a service based in the EU is de-facto "more" respectful of digital privacy.
You can read the comments on threads related to the EU tech where you will find people defending to the very end that privacy is better in the EU and that EU providers will never stoop as low as their US counterparts.
As always the truth is a lot murkier than that.
Yes, some services based in the EU are better in terms of privacy but it's not a given for all of them and it depends entirely on the service. Unfortunately such a nuanced take is not wildly popular in the tech world in this day and age where every US company is labelled as an evil data hungry entity and EU companies are portrayed as saints in this regard.
That's where the first problem lies.
The second problem is that for years now, people have been singing the praises of Mistral as a privacy friendly alternative the the US juggernauts because Mistral's headquarters is located in the EU and unfortunately today it seems some people are waking up to the fact that Mistral is doing the same thing than its US counterparts and they are disappointed which is understandable.
Who is to blame for this dichotomy? Is it Mistral who leaned too much on this marketing angle (the European Chatgpt without the invasive tracking/ better privacy settings) or is it the users who failed to realize that EU or not, Mistral wasn't going to pass on the opportunity to improve its models this way?
My hunch is that it's both.
You can't reasonably expect every individual employee on a Team plan to remember to dig into their personal settings and flip a privacy toggle. For any company dealing with sensitive IP or GDPR-compliant data, this basically makes the Team tier unusable.
Defaults matter more than the blog post. "You can opt out" is not the same product as "the org can actually enforce opt out."
you can't make this shit up