Can I opt out of my input or output data being used for training?
help.mistral.ai
help.mistral.ai
For some time these pages conflicted with what our users reported (they said that in contrast to what I stated to our management they found they were opted into training on prompts by default as per their own privacy page). Mistral just now corrected their docs. I'm not sure how long the conflicting situation has lasted, but at least for several days.
For contrast: Claude disables training on prompts for organizations starting from the 18 euro tier [0]. As a European I'm disappointed.
I know I'm naive but I expect that when I pay, this stuff is simply off, so I was already surprised by the Pro plan. But I did look out for it there, because Anthropic made this switch some time ago.
The English term for that is "opt out" not "opt in." To opt is to choose. If something is on by default, you have not opted in. You were forced in, and turning it off means you must opt out. (I.e., choose to be out.)
normally I wouldn't care about a mistake like this, except that opt in/out are very important concepts in software development and hacker culture. And it reversed the meaning of the original comment in a highly confusing, relevant way.
Note that I’m not using English grammar as my argument; human language (and English especially) has plenty of exceptions and expressions which make little sense, and if people were to adopt this phrasing en masse, it would naturally become a part of the language, whether it makes sense or not. My argument is that adopting this phrasing is a terrible, user-hostile decision and in my honest opinion we really, really, really ought to avoid it.
Now granted, he did not say that, and I only reached that conclusion by the rest of this conversation, but I think to have meant that and said '... was now also opt-in by default...' isn't unreasonable.
Just sharing since you mentioned you couldn't see how using that term for the opposite would make sense.
"Opting someone else in" is essentially the same category of error as "consenting for someone else". People can only consent for others in specific circumstances and even then only for specific people (e.g. legal guardians), trying to argue "but I consented for them!" in front of a judge usually ain't gonna work.
In other words, you can explicitly choose something by yourself, but if other people (in this case companies, service providers) choose something for you, it’s no longer your explicit decision made by yourself. Hence why I believe we can’t consider that ‘opting in’.
> The property of having to choose *explicitly* to join or permit something; a decision having the *default option being exclusion or avoidance*; used particularly with regard to mailing lists and advertising.
You're just using the term wrong. That's okay, I've used words wrong before, and it just means you've been presented an opportunity for learning a new fact.
But there's no argument to be had except with the dictionary.
No, it's really not. It should read "opted in to training on prompts by default".
"Opt in" means "you have to affirmatively turn this thing on". "Opted in" means "the thing is currently enabled".
Which is why it's probably better to write it as "enabled by default". Much harder to misinterpret.
"Opt in" and "by default" are contradictory phrases. They mean literally the opposite of each other. The only reason it's coherent is that most native speakers will elect to believe "by default" was used correctly because it's the easier to use term.
> there is not a rule of the English language that would make their usage unacceptable
I think you're using emotionally inflammatory language, possibly unintentionally. no one is refusing to accept what they wrote.
That being said, the way they used "opt in" is categorically wrong. It's the opposite of the dictionary definition.
https://en.wiktionary.org/wiki/opt-in
> The property of having to choose explicitly to join or permit something; a decision having the default option being exclusion or avoidance; used particularly with regard to mailing lists and advertising.
I understand what you're saying here, but maybe "turned on by default" is less confusing for everyone.
In theory also for individuals?
At least I have that toggle to deactivate that. But how would I ever know if they actually respect that?
Laws are violated all the time. The graveyard is full of people who had the right-of-way at a crosswalk ...
Companies violate them all the time and massive leaks happen a lot.
The punishments are trivial.
The only company you could think of trusting is one where an external , independent auditor is doing its work.
Your comment is perplexing. No company on earth meets your requirement. What are you expected to do? Move to a hut in the woods?
I'm so burned out on the bullshit companies that succeed in tech forcing their will upon us serfs that I'm actively looking into that very thing at this time. Tech used to be fun. Now it's just depressing. I'm ready to go back and take the blue pill.
Criminalize failure to keep private data private. Arrest CEOs and executives. Put them in jail when it happens.
And getting the data is not hard, they already have it. Risky is indeed a bit making use of that data, as that requires at least some humans (as potential whistleblowers). But you don't even have to tell them, where the data came from.
Whether they do it? No idea, I assume not, but I see a risk.
People always want to overcomplicate everything to benefit 5 super rich people that got rich taking wages from workers and ripping off retail investors. Please stop the pandering. Vote for yourself and your neighbors, don't vote to eliminate privacy so a rich pervert gets to exploit you.
Local hosting will be a solution, once the hardware becomes affordable.
The 90% tax bracket in the 1950s capped CEO and investor yearly income to the 2026 equivalent of 5mil a year. Use that imaginative brain that likes to speculate instead of learning history to image how our entire society changes if no individual can earn more than 5mil a year in all income sources. We also banned stock buybacks and had more regulations put in place after the 1929 collapse and great depression. Those things were removed slowly over the 60s and 70s until a lot was gutted all at once in the 80s. The final blows came in the 00s.
All the problems that existed leading up to and during the great depression are back because we reverted all the laws and policies that were put in place to prevent it from happening again.
None of this is complicated. Stop worrying about culture nonsense or right wing nonsense. Start voting to tax rich like we did in the 1950s.
Why did we have so many local and regional stores back then, but only a handful of conglomerates today? There is no incentive to merge companies by CEOs when it turns two 5mil a year CEO jobs into one 5mil a year CEO job. In that environment, merging is due to actual company need, not CEO enrichment.
CEOs will also stop cutting wages, under staffing, and outsourcing. It all stops because they no longer get paid more doing it. This is actual US history, the country boomed economically because of those tax rates and financial regs. This is not something anyone gets to deny, it already happened.
Voting against a proven solution is madness.
For the Team and Enterprise plans de default is "not sharing prompts for training" (which I mistakenly referred to as opted out of sharing prompts for training.) [1]
There is a toggle on https://admin.mistral.ai that allows you to disable training for both Vibe and Console/API for your entire organisation. And I'm not on the enterprise plan. I've disabled training the first time I created an account, and it has remained that way.
You story is also very confusing due to the wording around "opt-in by default" and "disappointed [about] opt-in to training" (most people would be disappointed about an opt-out) and probably conveys the wrong message to most people.
Sorry, I have always thought that "opting in" is, "opting for the presented option" and opting out is "opting out of it", so opting out [of sharing prompts for training] is choosing to not share, but apparently I was wrong my whole life. I'm not a native speaker, and I think most people here (in my country) would interpret this the way I do? Weird but TIL.
Opt-out = "we assume you are in unless you tell us you want to be out"
Opt-in and opt-out describe the nature of the choice that you make. “Opt” means to choose (apparently it is a French word we stole). Opt-in means you have to proactively choose to be in. Opt-out means you have to proactively choose to be out. “Opt-in by default” is an overly verbose way of saying “opt-out.”
In either case it describes the choice that you need to proactively make to override the default behavior.
Edit: I should also say that it is a “known point of contention” where pro-privacy people have been pushing back on this phrasing. So, you have probably accidentally stumbled into an ongoing discussion, which is why some of the comments might be unexpectedly prickly.
Yes, because people will say that something should be opt-in, meaning off by default, and then someone makes it on by default and says 'oh, it's opt-in, you're just opted in by default!'
You don't see "Allow the use of your interactions with Vibe to train Mistral’s AI models" at https://admin.mistral.ai/vibe/privacy ?
And "Allow the use of your API calls to train Mistral’s AI models" at https://admin.mistral.ai/plateforme/privacy ?
at https://admin.mistral.ai/vibe/privacy:
Allow public sharing of chats content
Allow user feedback on model responses
Chat Retention Policy
At https://admin.mistral.ai/plateforme/privacy I see
Allow the use of your API calls to train Mistral’s AI models.
Enable Labs models
So indeed, no "Allow the use of your interactions with Vibe to train Mistral’s AI models". I only see that setting here: https://chat.mistral.ai/chat?profile_dialog=privacy And I have to ask every user in my org to go and turn it off.
Also explains that the community support in Discord insisted that the toggle should be there, moreover they told me the individual toggles on the user's pages wouldn't do anything because it defaulted to "off" for any organization, as per their docs until 2 days ago. But that changed.
"Vibe (Teams): Administrators can disable data training usage for the entire organization."
That’s nice! Except that it was on for my entire org so I’ll be checking if they didn’t store anything first thing tomorrow. I wonder what changed their minds.
Saying "we were disappointed to be opted in to training by default" clarifies the point you're trying to make, which is that the toggle (whatever it may be called) was set to training by someone else, not you.
Actually in your case you'd say "...after being disappointed that the Pro tier opted us in to training on prompts by default", which gives an explicit subject ("the [Mistral] Pro tier"). No one will confuse that with the opposite "the Pro tier opted us out of training on prompts by default".
“disappointed that the Pro tier was opted-in to training on prompts by default” [and required manually opting out]
“the Team tier was now also opted-in by default” [and required manually opting out]
In context of each sentence and the larger comment, read smoothly here.
Also - have seen more than one lively discussion on these phrases, since defaults can stick 95% of the time and Big Tech has done their best to be abusive about what they automatically enable for users by default for some time.
That's called opt-out.
To those wondering, "opt" means to choose. "Opt in by default" makes no sense because you didn't choose; this is just "in by default". If they give you an option then it's called opt out. Opt in would be "out by default" with the option to go in.
"A bug in our portal had the setting for training inverted. This means that when you expected us not to be training on your data, we actually were. We know this adversely impacts the trust our users invested in us, so as of today we are crediting all affected accounts with $200 to use on our latest models".
> In choosing to submit, create, generate, record, post, or display Inputs on or through the Service, you grant an irrevocable, perpetual, transferable, sublicensable, royalty-free, and worldwide right to SpaceXAI to use, copy, store, modify, process, adapt, transmit, distribute, reproduce, publish, upload, download, display in public forums, list information regarding, make derivative works of, and distribute such Content, including anything referenced therein, in any and all media or distribution methods now known or later developed, for any purpose, and to aggregate your User Content and derivative works thereof for any purpose, including but not limited to: (i) maintain and provide the Service; (ii) improve our products and the Service and for our other business purposes, such as data analysis, customer and market research, developing new products or features, or identifying or displaying usage or User Content trends; and (iii) perform such other actions to enforce these Terms, comply with our Privacy Policy, comply with applicable law or governmental, court, and law enforcement requests or requirements or keep our Service safe.
> To the extent the User Content includes a person’s image, likeness, voice, or other similar attributes, you grant SpaceXAI the same rights to use those attributes as part of the User Content as described above. You represent and warrant that you have obtained all rights, licenses, notices, permissions, and consents necessary for SpaceXAI to use that User Content.
"Opt-in" means that the default is non-participation, for example, not training on your prompts. Is it possible that you intended to say "opt-out", which means that the default is participation? That's what the context seems to suggest.
See, for example, https://termly.io/resources/articles/opt-in-vs-opt-out/:
> Data privacy laws like the GDPR and CCPA give individuals the right to opt in or out of different data processing activities.
> · Opt in consent means the user takes an action to show they agree to something,
> · Opt out consent is when they take an action to say no.
Or https://bigid.com/blog/opt-in-vs-opt-out-consent/:
> • Opt-in consent requires users to actively agree before data collection or processing.
> • Opt-out consent allows data collection by default unless the user declines.
This is an important distinction, because confusing the two (as you seem to be doing) can lead you both into unethical fraud and legal liability.
> opt-in by default
Sorry to nitpick but the scheme you’re referring to is called “opt-out.”If such a data sentinel did exist then we might see them change their behavior
> and at the same time seemed to have lost the ability to centrally disable training on prompts for your entire organization
vs
> Vibe (Teams): Administrators can disable data training usage for the entire organization.
Is the document out of date? Or did Mistral reinstate this ability after the fact? What's the story here? Others seem to be stating they have and have had the ability to opt out of training centrally for a long time.
EDIT: Oh, it is addressed just a bit hard to find with all the opt in/out explanations: https://news.ycombinator.com/item?id=49549102
“Vibe (Teams): Administrators can disable data training usage for the entire organization.”
Was added to tfa. And I now see an org wide toggle where there was none before! Sadly it was on so I hope no users submitted stuff in the mean time, but it’s something!
The idea that they'll steal from everyone except you is just wishful thinking
I get this cynical conspiratorial energy, it fits the internet well, but I can assure you most people with even mild business sense would be intensely opposed to this idea. Well, except maybe Zuckerburg, but they don't really do enterprise anyway.
by this logic every business contract in tech is just a bunch of lies and means nothing and the only way to do anything is to have a server sitting next to you, otherwise it's "someone else's computer"
At this point, the reputation of the business matters too. Fable explicitly didn't support zero-retention usage, and it saw significantly lower adoption vs other flagship models, and their past releases. Being caught abusing enterprise contracts is really hard to dig out of.
Instead, confidentiality includes not literally copying material, not using trade secrets or inventions, and not using knowledge of business dealings for your own purposes.
So, while I fully expect that the big labs don't train on private material to the extent that they do those things in a blatant way, it would not be surprising if they pushed the boundaries. Humans push the boundaries all the time.
Up until now, machines did not have judgement, so if you set up a machine in such a way that you hadn't ensured it couldn't violate contract, you were culpable. But now that they have some kind of judgement, maybe it's enough to avoid liability to tell it to obey the contract, even if you give it incentives not to. After all, that's how it works with human employees, isn't it?
Perhaps now we have machines that understand language, someone somewhere is working on getting them to understand "a nod and a wink" as well.
1. Child porn
2. Stolen music
3. Private github repos, before that was 'stopped'
4. Illegally pirated books
Them training on company prompts against the terms of service would be one of the least bad things that these companies have trained AI models on
Why do you think a company - willing to break the law for child porn - won't break the law when it comes to your personal data?
(And they totally won't do it again they swear, the contract says so)
It wasn't "catastrophic" for the largest of the 3 US credit reporting agencies when their entire dataset was breached. The company is 100% IP and the only value they have was completely copied. Their largest value is to verify identities by the things Americans know (KDB) and after that "single factor of identity" was 100% compromised, the company only got bigger and more contracts.
When there are only 4 competitors in the large scale foundation model business and they all throw caution to the wind because they are racing to own the "$30 trillion TAM" they are all going to make critical security, RBAC, and segregation mistakes.
Both ChatGPT and Claude threads marked for sharing have been indexed in Google at large scale. This is incredibly easy to tell Google crawlers via robots.txt not to crawl those URLs, but nobody at either of these uber unicorns could be bothered to add that one pattern to the one file.
And all of the skepticism here is about verifiability. The foundation model companies are liable for potentially more the companies are worth if found to be violating copyrights of content used for training. They aren't going to make it easier for lawsuits against them by detailing their data ingestion into training pipeline.
1. Ensure security barriers are weak or honor based.
2. Put individual researchers under a lot of pressure.
3. If you get caught, blame the weak barriers, or the individual researcher.
Basically setup the incentive structure to incentivize researchers sticking their mittens in the private cookie jar while putting the cookie jar in a dark unmonitored/unsecured room with a sign on the door saying please don't enter.There's no reliable way to verify a foundation model has been trained on a particular piece of proprietary data. If an API key is ingested, hopefully the foundation model is wrapped in enough moderation that the raw API key oberserved during training is not recited verbatim in the output.
Why aren't people calling in prescriptions for themselves? I guess it just kinda runs on trust me bro and the threat of being put in prison.
But I can guarantee you that if a companies internal data got leaked or misused, then every single enterprise customer of that lab would turn around and start suing them. As an enterprise customer you would be foolish not to, if only if figure out via discovery just how badly you got screwed.
You want to see how nasty that can get. Just go and look at what Apple is doing to OpenAI at the moment. Do you really think Apple wouldn’t find a way to sue a lab into oblivion if they discovered a lab had secretly started training on their data?
Doesn't have to be outright lying, it can be something like "opt out" being off by default, and them opting you in at the next update without you noticing.
This is just a gut feeling and goes into the conspiratorial energy, but I'm pretty sure I can find countless examples of companies behaving like this in the past where it wasn't catastrophic (google meta amazon adobe ...)
> the legal protections for the consumer is much higher
You know you give away the right to file class action law suits against Anthropic when you accept their Terms Of Use, right? (at least the Americans ones)
Have been having a think about this statement. I agree in intent, some of them are probably breaking the agreement for training data. I dont think Microsoft is doing it, Enterprise Data Protection is the plank holding up their entire Copilot line. One whiff and everyone's gone. Copilot isnt actually good at anything except giving some illusion of protection, and preventing users from following a desire path to other LLMs without enterprise data protection. Its the core value proposition. But we only need to wait and see what the next 20 data breaches tell us to find out for sure.
In detail however, I dont know if they could just claim it as fair use, after exclaiming that they specifically wont do that. I dont think "Fair Use" would be the issue so much as contract law. I know a EULA wouldnt hold up the other way (By reading this you agree not to steal my data and train an LLM with it) for data thats made freely available on the internet. But if you are purchasing the "No Training" contract they would be in breach if they trained with it. Possibly fair use would let them keep the data after paying whatever they owe in terms of contract breach.
And yet, software companies are donating their means of production to these crooks left and right, hastening the day where they really will become obsolete. I'm sure others do equally unwise things.
If you're big enough, crime pays exceedingly well.
These AI companies are immensely valuable targets. When they get breached, their datasets will inevitably penetrate public datasets. And why would any AI company refuse to train on 'public' data?
If they are secretly scraping input prompts, that no longer becomes my problem. Someday, a massive lawsuit comes down, and everyone gets to play the victim.
You’re naive for thinking we don’t know how this really works.
If they stole your stuff and used in to train their model, what does it help if there is a lawsuit some years later which you most likely have no benefit from?
The point is that if someone accuses you of leaking data you can sue them for not abiding by contract, not that the data is not used for training
(To put it another way: if the copyright arguments against training on data scraped from the internet fail, the big AI companies don't really have a business, so they are going to proceed on the basis that they do until someone forces the issue otherwise. They don't need to train on data from their customers, and that is an argument that is almost certain to fail in court. If you're carrying 100kg of cocaine in your car, speeding is a really dumb idea, but the analogous action here would be firing a machine gun into the air from the driver's seat)
> If they are doing this and anyone can prove it, they are going to be sued very hard, and it will be a pretty straightforward case.
This is a joke, right? The usual settlement in these cases amounts to a few days worth of revenue.
Microsoft already did a rug pull on me and opted me in to training months after I signed up with Github Copilot. It exhausting and ultimately futile to monitor these companies.
It's not guaranteed that Duck.ai will continue to uphold its promise of not training on your sessions — if the company gets bought by Microsoft, it's only a matter of time before the switch to "you can opt out at any time". But since privacy is Duck.ai's brand, it will be somewhat harder for them to hide what they're doing should they betray their customers.
I also don't actually trust that Duck.ai sub-vendors OpenAI and Anthropic will uphold whatever contract they have with Duck.ai — the whole AI business model is built on lawless consumption of others work.
We'll ultimately have to run our own models locally, because it's impractical to defend against untrustworthy AI vendors.
I believe Apple has something similar too.
The page title is "Can I opt out of my input or output data being used for training".
Right at the top of the page it says "In certain cases, your input and output data (such as conversations, documents, and other user-provided content) may be included in Mistral’s model training programs. You retain full control over this processing and have the right to opt out of these programs at any time."
It's not the default on any Team plans and didn't used to be at Mistral (until last week or so). The team plan has a central admin role and page, and "seats".
And if it was the default, then I'd still expect a big button to turn it off for all seats, and not have to ask all user separately. But this changed over night and that button is not there. Although I expect it used to be, because some people here report that they have it.
I start the subscription, users report it is "on" by default, I ask support what's up, they say "sorry, docs should have been updated earlier but they are now". And they give me a lot of credits.
I just want to warn people, the Team sub just changed, docs were update too late, there was very little press about this (in my view) very important change. Actually, it is so important that I would not advice Mistral to our management if they'd use our prompts for training, so I take a TEAM sub so this is disabled for sure, or I can disable this org wide. But I can't anymore, now I have to ask each user/seat to disable sharing, and hope they do, I have no way to check. Way to inspire confidence. And their response: "You can still do this with the Enterprise subscription".
We flamed Anthropic for their switcheroo with their personal Pro plan a year ago [0], now Mistral does it with their business focused Team plan, so they deserve some fire imo.
....
"Of course we'll randomly turn that option off for you aka FB style and hope you don't notice. There is zero legal liability for us doing so, so why wouldn't we".
Their big play this year was to write a "whitepaper" on the future state of EU economy, which is something that they'd like to hand of to EU leaders and part of that proposal was some kind of mandatory 10% sovereign AI spend, or some other nonsense like that.
They are, at least, trying to make big enterprise (with tailored models, custom integration) and government policy plays.
That just goes to show you how ineffective they are as well at making AI click as a usecase.
And when they don't get ahead by their own terms they copy what they see ongoing with US AI labs. Le Chat, and Vibe.
They seem to get a lot of slack just because they're European but every new article I see about them makes my opinion a little worse
We've changed it to the article title now per https://news.ycombinator.com/newsguidelines.html.
Of course I’m not always on the most bleeding edge forefront of the latest hyped model so there might be better alternatives, but I’m happy with what they provide
Service: Vibe Plan: Non-Enterprise Default: Opted in Opt-out possible? Yes
Service: Vibe Plan: Enterprise Default: Opted out Opt-out possible? Yes (admin-managed)
Service: Mistral Studio/API Plan: Not specified Default: Not stated, I assume opted in Opt-out possible? Yes
But the individual level moral perspective confuses me. You object to your own input being used for training "for free", but you're ok to use models which already slurped the data of millions of other people "for free"?
I don't get it. Obviously this is going to be a controversial take on here (I am not blind to the sentiment), so, please help me understand. If you're a conscientious objector, why are you using the models in the first place?
I don't see any distinction between companies and people when it comes to moral objections re training data - at least, if that's a thing, I'm unaware of it.
I do agree with your last point re the hypocrisy.
But for my personal use, I'm totally fine with helping train the models.
I'll be called naive, but I'm on the optimist side of the fence here. I hope, and expect, AI actually frees us up and delivers much improved lives for everyone. I know this goes against the current zeitgeist, but it is genuinely what I think will happen rather than the dystopia most people predict.
All the other businesses have been bought up by VC, going to rental models, and looking for new and interesting ways to screw you over too.
Opt-out doesn't mean dick when the regulatory environment allows them to do things like the above without any recourse. Of course you can go to any other company that follows the exact same rules if you'd like.
So out of all the bad options this still seems to be one of the best
Regarding local models, Gemma, GPT-OSS, Nemotron, and Inkling (maybe upcoming Muse series as well) all are fairly decent options at a variety of hardware costs.
Why not link to the https://admin.mistral.ai/plateforme/privacy panel directly
https://alterlab.io/blog/how-to-give-your-ai-agent-access-to...
So no more data for them. No more social media, no more cloud storage, just no more.
It's been fun, but I am smarter than AI, so bye.
I'm assuming they've all at least thought about it quite hard, which is worrying in-and-of itself :).
Regarding the former, there's no normal Copy button so presumably this just copies the content of the article. Not sure why it needs to be clarified that its for LLMs.
I think you would be hard pressed to find any relevant tech company that doesn’t have a relationship with the Saudis or is funded by them - or any government for that matter…
I just wish I could force them to share it with their competitors also.
> Vibe (Enterprise): customers are opted out of training by default
So they made it opt in for enterprise (how it should be), but intentionally made opt out for regular user.Basically saying "screw you: to regular users.
Any self respecting user should stop using them.
I think I will be using Kagi Ultimate for the inference UI, so the data is somewhat anonymized before being collected.
Mistral has had, and continues to have, a toggle in the admin settings that permanently disables training on your data. The option has not been removed, and previous opt-outs are still honored. As far as I know, Mistral always trained on your data by default except for the enterprise plan, with the option to disable it on all plans, and with the option for organizations to make the choice for all your users.
Kagi Ultimate still uses mostly closed models by OpenAI / Anthropic, etc.
"Mistral always trained on your data by default except for the enterprise plan" - This is not true, until last week all docs stated that the use of your interactions with Vibe to train Mistral's AI models was off by default on the Team plan. Now that is only still the case on the enterprise plan.
Planning code changes with GLM-5.2 using a Mistral Studio API key and implementing code changes using the Mistral Vibe API key has worked well for me. At my basic subscription tier, Vibe will share data with Mistral. It works for me because, when it comes to privacy, I care less about the actual code and more about the planning / high-level stuff.
Same here, actually. I'm American but have had a Mistral sub to supplement local models. The Mistral models, IMO, are very hit or miss, and I was about to cancel my sub until I saw they added GLM.
Using Claude, Mistral and the rest of them is not going to solve your issue with data collection.
You can opt out in this one.
if you sign the contract (click I agree on Terms of Service), and it says that they do not train on the data, by what right can they backtrack on that?
Maybe it is assumed that they notified you and you have the right to terminate the contract? Relying on some clause where the contract can be updated at any time. Or terminated at any time (with the presumption that a clause change is a termination and an automatic signing of the new contract, but that's weak)
This is them just making it very clear and disclosing as per European rules.
Of course with Claude and so on this bothers me too, but it doesn't seem like there's any real recourse under US law. But I would hope that "oh you shouldn't enter PII" isn't going to cut it under European law, that if I say "don't store my prompts, they include PII I don't want you storing" should be sufficient here under the GDPR and Mistral shouldn't be able to just store it anyway.
Edit: Does “use for training” include “we store all your chat logs forever tied to your identity”?
Of course because you can’t be opt out by default that would be called opt in.
That's not the point though. The problem is that in the minds of lots of people including here on HN or otherwise, a service based in the EU is de-facto "more" respectful of digital privacy.
You can read the comments on threads related to the EU tech where you will find people defending to the very end that privacy is better in the EU and that EU providers will never stoop as low as their US counterparts.
As always the truth is a lot murkier than that.
Yes, some services based in the EU are better in terms of privacy but it's not a given for all of them and it depends entirely on the service. Unfortunately such a nuanced take is not wildly popular in the tech world in this day and age where every US company is labelled as an evil data hungry entity and EU companies are portrayed as saints in this regard.
That's where the first problem lies.
The second problem is that for years now, people have been singing the praises of Mistral as a privacy friendly alternative the the US juggernauts because Mistral's headquarters is located in the EU and unfortunately today it seems some people are waking up to the fact that Mistral is doing the same thing than its US counterparts and they are disappointed which is understandable.
Who is to blame for this dichotomy? Is it Mistral who leaned too much on this marketing angle (the European Chatgpt without the invasive tracking/ better privacy settings) or is it the users who failed to realize that EU or not, Mistral wasn't going to pass on the opportunity to improve its models this way?
My hunch is that it's both.
But fact of the matter is that the US is rapidly sliding into totalitarianism and at the same time US tech companies have an hu huge influence worldwide.
I commend any alternative that comes from outside the US and also offers an “open source” selfhosted option.
Got to love the private equity parasites ruining everything for the sake of profit.
you can't make this shit up