222 comments

[ 0.20 ms ] story [ 24.4 ms ] thread
Context: After careful research our organization preferred a European partner with good central privacy controls. We landed on Mistral, after being disappointed that the Pro tier was opt-in to training on prompts by default we switched up to the Team tier which provides an organization dashboard with some relevant settings. As we did that Mistral changed these options and the Team tier was now also opt-in by default and at the same time lost the ability to centrally disable training on prompt for your entire organization. This even caused some of our (testing) prompts to be used for training (which Mistral removed after we expressed our disappointment).

For some time these pages conflicted with what our users reported (they said that in contrast to what I stated to our management they found they were opted into training on prompts by default as per their own privacy page). Mistral just now corrected their docs. I'm not sure how long the conflicting situation has lasted, but at least for several days.

For contrast: Claude disables training on prompts for organizations starting from the 18 euro tier [0]. As a European I'm disappointed.

[0] https://claude.com/pricing#team-&-enterprise

“Opt in by default” would mean that it is not enabled by default. Do you mean opt out?
Yes, I found this comment very hard to understand until I realised they were talking about it being opt-out with no setting to change it. (At first I thought it was opt-in by default, and the "by default" implies that there is a setting to change the opt-in/opt-out setting)
"For contrast: Claude disables training on prompts for organizations starting from the 18 euro tier "

In theory also for individuals?

At least I have that toggle to deactivate that. But how would I ever know if they actually respect that?

If you don’t trust the company to keep their promise, don’t use their products.
I don't trust any company with their word on anything. Luckily, privacy policies are legally binding.
Why does that matter? Legally binding just means "slightly more expensive when we get caught"
> Luckily, privacy policies are legally binding.

Laws are violated all the time. The graveyard is full of people who had the right-of-way at a crosswalk ...

> Luckily, privacy policies are legally binding.

Companies violate them all the time and massive leaks happen a lot.

The punishments are trivial.

GPDR fines in the EU are NOT trivial.
How can you trust any company?

The only company you could think of trusting is one where an external , independent auditor is doing its work.

> If you don’t trust the company to keep their promise, don’t use their products.

Your comment is perplexing. No company on earth meets your requirement. What are you expected to do? Move to a hut in the woods?

> Move to a hut in the woods?

I'm so burned out on the bullshit companies that succeed in tech forcing their will upon us serfs that I'm actively looking into that very thing at this time. Tech used to be fun. Now it's just depressing. I'm ready to go back and take the blue pill.

Been there. Nice and peaceful, but can get lonely, though.
What company do you trust to keep their promise?
That is ridiculous. Vote to ensure products have to be legally private and make it a crime to share or reuse your data for anything. This should be the norm that people vote for. The idea that we have to give up privacy so some nerdy pervert can be a billionaire off the backs of people who do the work is absurd.

Criminalize failure to keep private data private. Arrest CEOs and executives. Put them in jail when it happens.

How do you know an LLM provider does not kill puppies every time you send a prompt longer than 14 words?
Because they have no incentive as a company to do that? But do have a strong incentive to learn from user input. (Most cutting edge features are developed private - very valuable to get that into your tool)

And getting the data is not hard, they already have it. Risky is indeed a bit making use of that data, as that requires at least some humans (as potential whistleblowers). But you don't even have to tell them, where the data came from.

Whether they do it? No idea, I assume not, but I see a risk.

We can easily make it a crime to collect the data and another crime to share it or store it in a way that allows someone else to copy it, authorized or not.

People always want to overcomplicate everything to benefit 5 super rich people that got rich taking wages from workers and ripping off retail investors. Please stop the pandering. Vote for yourself and your neighbors, don't vote to eliminate privacy so a rich pervert gets to exploit you.

And what would my vote change about the situation?

Local hosting will be a solution, once the hardware becomes affordable.

Vote for people who want to restore the 1950s federal tax rates that we already had in the 1950s. I find so sad that people ignore history and act like solutions don't already exist.

The 90% tax bracket in the 1950s capped CEO and investor yearly income to the 2026 equivalent of 5mil a year. Use that imaginative brain that likes to speculate instead of learning history to image how our entire society changes if no individual can earn more than 5mil a year in all income sources. We also banned stock buybacks and had more regulations put in place after the 1929 collapse and great depression. Those things were removed slowly over the 60s and 70s until a lot was gutted all at once in the 80s. The final blows came in the 00s.

All the problems that existed leading up to and during the great depression are back because we reverted all the laws and policies that were put in place to prevent it from happening again.

None of this is complicated. Stop worrying about culture nonsense or right wing nonsense. Start voting to tax rich like we did in the 1950s.

Why did we have so many local and regional stores back then, but only a handful of conglomerates today? There is no incentive to merge companies by CEOs when it turns two 5mil a year CEO jobs into one 5mil a year CEO job. In that environment, merging is due to actual company need, not CEO enrichment.

CEOs will also stop cutting wages, under staffing, and outsourcing. It all stops because they no longer get paid more doing it. This is actual US history, the country boomed economically because of those tax rates and financial regs. This is not something anyone gets to deny, it already happened.

Voting against a proven solution is madness.

Always assume and act as they won’t honor it.
This post is only about the defaults, and expectations therefore for Team and Enterprise plans and their organizational controls.
> and at the same time seemed to have lost the ability to centrally disable training on prompts for your entire organization

There is a toggle on https://admin.mistral.ai that allows you to disable training for both Vibe and Console/API for your entire organisation. And I'm not on the enterprise plan. I've disabled training the first time I created an account, and it has remained that way.

You story is also very confusing due to the wording around "disappointed [about] opt-in to training" and "opt-in by default" and probably conveys the wrong message to most people.

I don't have that toggle (but could indeed have sworn I saw it earlier).

Sorry, I have always thought that "opting in" is, "opting for the presented option" and opting out is "opting out of it", so opting out [of sharing prompts for training] is choosing to not share, but apparently I was wrong my whole life. I'm not a native speaker, and I think most people here (in my country) would interpret this the way I do? Weird but TIL.

FWIW I don’t find what you wrote confusing, but I do think it is following a sort of… bad convention that some companies have been pushing.

Opt-in and opt-out describe the nature of the choice that you make. “Opt” means to choose (apparently it is a French word we stole). Opt-in means you have to proactively choose to be in. Opt-out means you have to proactively choose to be out. “Opt-in by default” is an overly verbose way of saying “opt-out.”

In either case it describes the choice that you need to proactively make to override the default behavior.

Edit: I should also say that it is a “known point of contention” where pro-privacy people have been pushing back on this phrasing. So, you have probably accidentally stumbled into an ongoing discussion, which is why some of the comments might be unexpectedly prickly.

>Edit: I should also say that it is a “known point of contention” where pro-privacy people have been pushing back on this phrasing. So, you have probably accidentally stumbled into an ongoing discussion, which is why some of the comments might be unexpectedly prickly.

Yes, because people will say that something should be opt-in, meaning off by default, and then someone makes it on by default and says 'oh, it's opt-in, you're just opted in by default!'

I 100% agree that “opt-in by default” is bad and that “opted” in that sense is a bullshit incoherent phrase. Unfortunately this “opting as a thing that happens to you instead of a choice” idea has evidently been promoted well, so we have to expect that people will unknowingly use it.
And suddenly we have laws directing AI companies to report bad behavior or potential rival candidates.
And some shadowy departments do this without needing any laws at all.
“Opt-in” means to agree to something. If something is “opt-in by default”, it means that it is opt-out and someone is using weasel wording and contract inducements to force you into something you didn’t actually agree to. Any “disagreement” is just people trying to advocate for what they wished it meant.
> I don't have that toggle (but could indeed have sworn I saw it earlier).

You don't see "Allow the use of your interactions with Vibe to train Mistral’s AI models" at https://admin.mistral.ai/vibe/privacy ?

And "Allow the use of your API calls to train Mistral’s AI models" at https://admin.mistral.ai/plateforme/privacy ?

Mistral support just confirmed that the toggle was removed from the Team plan earlier this year and made exclusive to the enterprise tier. I bet that if you signed up earlier, they didn't remove it for your account, so it's only for new customers. Which explains some of the confusion here.

Also explains that the community support in Discord insisted that the toggle should be there, moreover they told me the individual toggles on the user's pages wouldn't do anything because it defaulted to "off" for any organization, as per their docs until 2 days ago. But that changed.

Ok it (org wide toggle) just returned and the docs were changed again!

That’s nice! Except that it was on for my entire org so I’ll be checking if they didn’t store anything first thing tomorrow.

(comment deleted)
I think there is a simple, unambiguous way to describe this, which is to use the passive voice or an explicit subject with the past tense to clarify that you didn't do the opting in.

Saying "we were disappointed to be opted in to training by default" clarifies the point you're trying to make, which is that the toggle (whatever it may be called) was set to training by someone else, not you.

Actually in your case you'd say "...after being disappointed that the Pro tier opted us in to training on prompts by default", which gives an explicit subject ("the [Mistral] Pro tier"). No one will confuse that with the opposite "the Pro tier opted us out of training on prompts by default".

I think the trouble with "opted in to training by default" is that there was no "opting", i.e. no choosing. I can't come up with a better suggestion off the top of my head though!
No you're not wrong, but while I can't speak for this specific instance, in many other cases, this language is intentionally confusing in order to dark-pattern users into agreeing to the thing they don't want to. Similar is using ambiguous language next to a switch/checkbox that makes it difficult to tell exactly what each state means.
Imho, legally, one should always be 'opted out' of 'forced mingling of your ideas' without deliberately opting in. Same as for advertising, click-through tracking, and sociopsycho/marketing metrics. Like the old firewall rule (easier to handle opt-in/out that way than firewalls; like, how many people can run a firewall that way now?). Users should have it right in front of their face when they install something or register, too, not hidden among options. It might take the user five or ten more minutes to get to use the app but worth it.
My native-US-English speaker read:

“disappointed that the Pro tier was opted-in to training on prompts by default” [and required manually opting out]

“the Team tier was now also opted-in by default” [and required manually opting out]

In context of each sentence and the larger comment, read smoothly here.

Also - have seen more than one lively discussion on these phrases, since defaults can stick 95% of the time and Big Tech has done their best to be abusive about what they automatically enable for users by default for some time.

It's understandable but it is technically inconsistent and dilutes the meaning of opt-in. Opt implies an active choice, so you never are opting for the default.
It's also simply bad writing regardless of what meaning the reader takes from it. "Enabled by default" or "Allowed by default" are much clearer and more natural phrasings without any connotations of the user having taken an action to express a choice.
I also have these toggles, while being on a free plan. I must have set them to disabled at setup because that's how they are now.
[delayed]
Yeah, it was confusing to read the parent before I realised they got the terms the wrong way around.

To those wondering, "opt" means to choose. "Opt in by default" makes no sense because you didn't choose; this is just "in by default". If they give you an option then it's called opt out. Opt in would be "out by default" with the option to go in.

Today I registered a free account with Grok, because I simply was curious. Man, training is "off" by default even with the free tier. I was positively surprised. As a European I'm disappointed too.
Grok has possibly the worst ToS of any of the AI providers. They are probably different in the EU, but:

> In choosing to submit, create, generate, record, post, or display Inputs on or through the Service, you grant an irrevocable, perpetual, transferable, sublicensable, royalty-free, and worldwide right to SpaceXAI to use, copy, store, modify, process, adapt, transmit, distribute, reproduce, publish, upload, download, display in public forums, list information regarding, make derivative works of, and distribute such Content, including anything referenced therein, in any and all media or distribution methods now known or later developed, for any purpose, and to aggregate your User Content and derivative works thereof for any purpose, including but not limited to: (i) maintain and provide the Service; (ii) improve our products and the Service and for our other business purposes, such as data analysis, customer and market research, developing new products or features, or identifying or displaying usage or User Content trends; and (iii) perform such other actions to enforce these Terms, comply with our Privacy Policy, comply with applicable law or governmental, court, and law enforcement requests or requirements or keep our Service safe.

> To the extent the User Content includes a person’s image, likeness, voice, or other similar attributes, you grant SpaceXAI the same rights to use those attributes as part of the User Content as described above. You represent and warrant that you have obtained all rights, licenses, notices, permissions, and consents necessary for SpaceXAI to use that User Content.

https://x.ai/legal/terms-of-service

> being disappointed that the Pro tier was opt-in to training on prompts by default

"Opt-in" means that the default is non-participation, for example, not training on your prompts. Is it possible that you intended to say "opt-out", which means that the default is participation? That's what the context seems to suggest.

See, for example, https://termly.io/resources/articles/opt-in-vs-opt-out/:

> Data privacy laws like the GDPR and CCPA give individuals the right to opt in or out of different data processing activities.

> · Opt in consent means the user takes an action to show they agree to something,

> · Opt out consent is when they take an action to say no.

Or https://bigid.com/blog/opt-in-vs-opt-out-consent/:

> • Opt-in consent requires users to actively agree before data collection or processing.

> • Opt-out consent allows data collection by default unless the user declines.

This is an important distinction, because confusing the two (as you seem to be doing) can lead you both into unethical fraud and legal liability.

  > opt-in by default
Sorry to nitpick but the scheme you’re referring to is called “opt-out.”
I don't trust any of these companies with my data, and I assume that whatever data they've got is going to be used, one way or another, no matter what they tell you. It would be nice if you could stick a sentinel in your data that if it ever shows up in the models you know they've broken the rules for sure.
Yeah. Unfortunately they know you can't catch them on this so they feel absolutely free to do whatever they please

If such a data sentinel did exist then we might see them change their behavior

Buried by the distraction of the semantics of "opt in" vs "opt out", the more interesting conflict isn't addressed in the sibling threads.

> and at the same time seemed to have lost the ability to centrally disable training on prompts for your entire organization

vs

> Vibe (Teams): Administrators can disable data training usage for the entire organization.

Is the document out of date? Or did Mistral reinstate this ability after the fact? What's the story here? Others seem to be stating they have and have had the ability to opt out of training centrally for a long time.

EDIT: Oh, it is addressed just a bit hard to find with all the opt in/out explanations: https://news.ycombinator.com/item?id=49549102

You are right! They must have just now switched this back, I also have the toggle now! It was turned on sadly but it’s something.
Just now the sentence:

“Vibe (Teams): Administrators can disable data training usage for the entire organization.”

Was added to tfa. And I now see an org wide toggle where there was none before! Sadly it was on so I hope no users submitted stuff in the mean time, but it’s something!

Taking away the ability to centrally enforce an opt-out across an organization is a massive red flag.

You can't reasonably expect every individual employee on a Team plan to remember to dig into their personal settings and flip a privacy toggle. For any company dealing with sensitive IP or GDPR-compliant data, this basically makes the Team tier unusable.

Yes. If the privacy control only exists per user, it isn't a control for a team.

Defaults matter more than the blog post. "You can opt out" is not the same product as "the org can actually enforce opt out."

This isn't the case. There's a toggle on https://admin.mistral.ai that allows you to disable training for both Vibe and Console/API for your entire organization, I just checked.
I think they removed the toggle for new customers (on the Team plan) because I don’t have it. If I had, I probably wouldn’t have posted this.

I mean it’s still annoying that I subscribe my org because they say the toggle is off, then find users telling me in fact it is on. Then to find that I can’t disable it org wide and have to ask each user to “please watch out” is pretty humiliating.

European innovation right here

you can't make this shit up

There are so models that beats all of Mistral models, plus you can run many of them locally. Why would anyone run Mistral?
Possibly because Mistral is a French-based company, so EU companies can cut the American umbilical cord a bit more.
EU companies can download GLM or Kimi-K3 and get way better performance, though? I don't see any case for using a Mistral model when much better open models exist.
Because not everyone has the infrastructure to run that with better performance? Anyway, Mistral serves GLM 5.2 through their global and European endpoints, so if you wanted to leverage their services and use a more powerful open model, that seems to be an option.
Most people don't want a second job trying to figure out self-hosted AI stuff.
To be honest, I have a hard time noticing differences with Claude (in Kiro) and Mistral Vibe, at least with what I use them for. They simply feel like talking to the exact same thing.
The OCR stuff is quite usable. Their models perform good at some very basic tasks, so I use them to diversify. But their current model lineup is really terrible.
To have at least a choice of using a European trained model. Downloadable weights is not open source. Mistral is able to respond to any regulatory queries about training data and concerns.
Haha, the answer is "european regulation"?
Pretty much. Europe is basically not at all involved in the AI race and is reliant on US and China.
Mistral attempts to create the regulations. They get too much credit just because they are European
Mistral OCR is really good and their small models are great for simple translations, I use them regularly.

Of course I’m not always on the most bleeding edge forefront of the latest hyped model so there might be better alternatives, but I’m happy with what they provide

Their OCR did worse at reading a 40 page PDF of printed text than tesseract for me, I just paid $2 for useless output
Qwen 3.8 27B absolutely demolishes Mistral best offerings at coding, and you only need a 5090 or 2x3090 to run it.
Sovereignty. Not everything is about performance.
It’s a spyware, but a sovereign one
How so? I've opted out of using my data for training.
Defaults matter. The expectation for an organization tier plan is not that you have to go and ask each user in your org to please turn off "Allow the use of your interactions with Vibe to train Mistral's AI models" before starting your work.
How many times with large companies have you found that they removed the old opt-out value and put a new one in that is enabled by default because of course it's opt-out?

Opt-out doesn't mean dick when the regulatory environment allows them to do things like the above without any recourse. Of course you can go to any other company that follows the exact same rules if you'd like.

Tbh there is much more regulatory pressure on EU AI companies than US/China - of course you can only use local models which Mistral actually releases unlike the US alternatives.

So out of all the bad options this still seems to be one of the best

I'm curious what regulatory pressure there is on EU AI companies that wouldn't apply to many of the US firms. The AI Act and GDPR still apply to the tech giants since they operate in the EU (e.g. Anthropic watermarking). There are labor laws that are definitely more strict but many of the US firms have operating presence in the EU as well. I imagine that being directly in the EU probably does increase regulatory oversight but I'm curious how this would manifest in Mistral in particular.

Regarding local models, Gemma, GPT-OSS, Nemotron, and Inkling (maybe upcoming Muse series as well) all are fairly decent options at a variety of hardware costs.

These laws apply to US companies in a more limited way because if we fine them too much they complain to US government that other countries have laws they have to follow. And then the US government intervenes to protect their money and data/intelligence extraction machinery (big tech companies). Usually with at least partial success.
Oh come on. So you should be fine with this because "hey we're the friendly europeans..."?
I mean they all do it right ? Mistral is just the first one to publicly say it.
Same company that has a partnership with Saudis, btw.
This means exactly what?

I think you would be hard pressed to find any relevant tech company that doesn’t have a relationship with the Saudis or is funded by them - or any government for that matter…

Yeah, let's just sweep it under the rug then!
Nah but be a little bit more specific than just sprinkling random FUD - what is the relationship and why is it problematic ?
I could be mistaken, but wasn't Mistral openly championing themselves as a company and EU option that wouldn't do this/didn't do this?
You must have not been keeping up with the times :)

Their big play this year was to write a "whitepaper" on the future state of EU economy, which is something that they'd like to hand of to EU leaders and part of that proposal was some kind of mandatory 10% sovereign AI spend, or some other nonsense like that.

They are, at least, trying to make big enterprise (with tailored models, custom integration) and government policy plays.

That just goes to show you how ineffective they are as well at making AI click as a usecase.

And when they don't get ahead by their own terms they copy what they see ongoing with US AI labs. Le Chat, and Vibe.

That just sounds like exactly the same as the US companies are doing with their government (trying to get a lot of money out of them)
The same mistral that has a patent for "code implemented tool calls"https://news.ycombinator.com/item?id=49243397#49243588 and said "Companies selling artificial intelligence models in Europe should pay a "levy" to support cultural industries".

They seem to get a lot of slack just because they're European but every new article I see about them makes my opinion a little worse

This gets posted literally moments before I was about to pay them after ditching Claude. Thank you! I hate data collection in paid products.

I think I will be using Kagi Ultimate for the inference UI, so the data is somewhat anonymized before being collected.

My best experience with Mistral has been with their expensive GLM-5.2 model. It's actually developed by Z.ai, but unlike Z.ai, the GLM-5.2 at Mistral can be used at a low price without training on your prompts - but only if you remember to hit the privacy toggle in their admin settings.

Planning code changes with GLM-5.2 using a Mistral Studio API key and implementing code changes using the Mistral Vibe API key has worked well for me. At my basic subscription tier, Vibe will share data with Mistral. It works for me because, when it comes to privacy, I care less about the actual code and more about the planning / high-level stuff.

> My best experience with Mistral has been with their expensive GLM-5.2 model. It's actually developed by Z.ai, but unlike Z.ai, the GLM-5.2 at Mistral can be used at a low price without training on your prompts - but only if you remember to hit the privacy toggle in their admin settings.

Same here, actually. I'm American but have had a Mistral sub to supplement local models. The Mistral models, IMO, just aren't very good, and I was about to cancel my sub until I saw they added GLM.

Thanks for the pointer! I had set up mistral a while back using pi to compliment my local Qwen usage, but I found Qwen to just be better for all of my tasks at a substantially cheaper price, and reasonably fast tps. I also tried signing up for z.ai, but they would never send me an email to sign in. Using GLM through mistral to compliment my local models seems like exactly what I want.
Qwen is leaving a strong impression on me as well. Qwen-3.8-Max via openrouter has been a strong performer for me. I run it in autolith and then have claude code check the commits. Claude highly praises the quality of the work. Lol
Just run your LLMs locally instead of using external providers.

Using Claude, Mistral and the rest of them is not going to solve your issue with data collection.

> I hate data collection in paid products.

You can opt out in this one.

You can, but you still have to opt-out. It'd be better if it was by default.
You can still easily disable "Allow the use of your interactions with Vibe to train Mistral's AI models." What's annoying is that they switched this to on by default on Team plans with no way to turn it off for your whole team/org, this week.
I assume they do this no before releasing new models. It feels like they expect higher user influx from their new models.
This is a hugely misleading editorialised title.

The page title is "Can I opt out of my input or output data being used for training".

Right at the top of the page it says "In certain cases, your input and output data (such as conversations, documents, and other user-provided content) may be included in Mistral’s model training programs. You retain full control over this processing and have the right to opt out of these programs at any time."

This is the case for all the major AI providers. Training collection is on by default, but you can opt out.
"No model training on your content by default" [0]

It's not the default on any Team plans and didn't used to be at Mistral (until last week or so). The team plan has a central admin role and page, and "seats".

And if it was the default, then I'd still expect a big button to turn it off for all seats, and not have to ask all user separately. But this changed over night and that button is not there. Although I expect it used to be, because some people here report that they have it.

https://claude.com/pricing#team-&-enterprise

Agreed. I read the title as they would start using my data for training and I couldn't opt-out. After looking at the page and checking my app (I have Pro subscription) it seems like I can opt-out and my initial opt-out when I subscribed was preserved.
When I started my search for an AI "partner" the Mistral TEAM plan had "use my prompts for training" turned off by default, as per their docs in multiple places. I could have sworn I saw a organization switch in my dashboard for this setting org wide, but am not sure.

Then I start the subscription, users report it is "on" by default, I ask what's up, they say "sorry, docs should have been updated earlier but they are now". And they give me a lot of credits.

I just want to warn people, the Team sub just changed, docs were update too late, there was very little press about this (in my view) very important change. Actually, it is so important that we would not use Mistral if they'd use our prompts for training, so I take a TEAM sub so this is disabled, or I can disable this org wide. But I can't anymore, now I have to ask user to disable sharing, and hope they do. Way to inspire confidence.

"You can opt out at any time"

....

"Of course we'll randomly turn that option off for you aka FB style and hope you don't notice. There is zero legal liability for us doing so, so why wouldn't we".

This is a European company, there absolutely is legal liability. The GDPR expressly prohibits using customer data for a purpose other than the one the customer intended and consented to.
Very disappointing. I really get the sense that all AI companies and anti-privacy parasites on society.
Most commenters here clutching their pearls as if Claude and Gemini Pro didn't do it already. In the latter you (as a paying customer) can't even store the chat history unless you agree to their 'improvement of services'. Do you have all your accounts paid for by the enterprise or you never check the settings?
> Most commenters here clutching their pearls as if Claude and Gemini Pro didn't do it already.

That's not the point though. The problem is that in the minds of lots of people including here on HN or otherwise, a service based in the EU is de-facto "more" respectful of digital privacy.

You can read the comments on threads related to the EU tech where you will find people defending to the very end that privacy is better in the EU and that EU providers will never stoop as low as their US counterparts.

As always the truth is a lot murkier than that.

Yes, some services based in the EU are better in terms of privacy but it's not a given for all of them and it depends entirely on the service. Unfortunately such a nuanced take is not wildly popular in the tech world in this day and age where every US company is labelled as an evil data hungry entity and EU companies are portrayed as saints in this regard.

That's where the first problem lies.

The second problem is that for years now, people have been singing the praises of Mistral as a privacy friendly alternative the the US juggernauts because Mistral's headquarters is located in the EU and unfortunately today it seems some people are waking up to the fact that Mistral is doing the same thing than its US counterparts and they are disappointed which is understandable.

Who is to blame for this dichotomy? Is it Mistral who leaned too much on this marketing angle (the European Chatgpt without the invasive tracking/ better privacy settings) or is it the users who failed to realize that EU or not, Mistral wasn't going to pass on the opportunity to improve its models this way?

My hunch is that it's both.

No one is saying that every US company is an evil data hungry entity and EU companies are saints.

But fact of the matter is that the US is rapidly sliding into totalitarianism and at the same time US tech companies have an hu huge influence worldwide.

I commend any alternative that comes from outside the US and also offers an “open source” selfhosted option.

My bet is that mistral models will suddenly start to shine.
Summary of the different scenarios

Service: Vibe Plan: Non-Enterprise Default: Opted in Opt-out possible? Yes

Service: Vibe Plan: Enterprise Default: Opted out Opt-out possible? Yes (admin-managed)

Service: Mistral Studio/API Plan: Not specified Default: Not stated, I assume opted in Opt-out possible? Yes

Very disappointing, but who doesn't train on user data? It's the only moat they have
I had the option, and had it disable everywhere, manually. The only one I didn't use, at all, is Anthropics service because of iffy Dario aura and their terms of service. Where is training in user data enforced and not possible to opt out?
I'm sure that the 3 users they have are very pissed about this news.
LeChat when it was launched as a consumer product was always going to be a data acquisition play.

This is them just making it very clear and disclosing as per European rules.

Just to achieve a great ideal: MEGA Make Europe Great Again.
I'd be interested in some legal/GDPR takes on PII handling in prompts. If someone enters PII into a prompt, and Mistral retains it for training, is it sufficient for them to say "don't enter PII into prompts?"

Of course with Claude and so on this bothers me too, but it doesn't seem like there's any real recourse under US law. But I would hope that "oh you shouldn't enter PII" isn't going to cut it under European law, that if I say "don't store my prompts, they include PII I don't want you storing" should be sufficient here under the GDPR and Mistral shouldn't be able to just store it anyway.

They might circumvent this by adding a prompt like "remove PII from this prompt", so I don't think it's a worthwhile route. The issue exists whether PII is input or not, like IP or secrets.
the rapid enshittification in LLM hype cycle is something else.

Got to love the private equity parasites ruining everything for the sake of profit.