Change record
CA-C-004769
OpenRouter Privacy Policy
Entity
Date detected
September 1, 2026
Severity
Direction
Neutral
Taxonomy
Disclosure requirement change
Changes
+19 sentences added · 6 sentences modified

Impact Summary

Medium Neutral for users
Affected users
All users Minors Users under 18

OpenRouter expanded its privacy policy to address file storage through a Files API feature, establishing how uploaded files like images, PDFs, and documents are handled, transmitted to model providers, encrypted, and retained until deletion or account closure. The policy also raised the minimum age requirement from 13 to 18 years old. These changes introduce detailed operational procedures for persistent file storage and clarify user eligibility.

2 new obligations 1 obligation expanded

Consumers: You must be at least 18 to use OpenRouter; younger users are no longer eligible.

Consumers: Files you upload are encrypted and OpenRouter staff cannot routinely access their contents.

Data controllers: When you delete files or close your account, OpenRouter will work to remove them from all systems within specified timeframes.

Stay ahead of the changes
Track OpenRouter and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF

What this means for you

The updated policy raises the minimum age to use OpenRouter from 13 to 18 years old, meaning users under 18 are no longer eligible. For users who upload files through the Files API feature, the revised terms establish specific handling procedures: files are encrypted at rest and in transit, transmitted to model providers you select, retained until deletion or account closure, and not used for training or marketing purposes. The policy specifies that access is restricted to automated systems necessary to operate the service, and manual access occurs only for investigating violations, responding to legal process, or providing support. You can delete uploaded files at any time, which triggers removal efforts from active systems and backups within timeframes specified in the Data Processing Agreement.

What you can do

If you are under 18 and currently use OpenRouter, review the updated policy to understand that your access may be restricted as of the effective date.

If you use the Files API to upload documents, you may delete files at any time through your account; deleted files will be removed from active systems and backups per OpenRouter's Data Processing Agreement.

Key Clauses Affected

Minimum age requirement

Raised from 13 to 18 years old, excluding minors from platform access.

Files API data handling

Establishes encryption, retention, deletion, and access control procedures for persistently uploaded files.

Prohibited file use

Explicitly states uploaded files are not used for model training, unrelated analytics, or marketing.

Full clause-by-clause analysis available with Insight.

This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology

Evidence Verification

✓ Verified
Previous Version
c22c1ebf931a841a6b695d9db441ce28877a40e2b39c88c0c551743da2d72d54
August 26, 2026 01:29 UTC
✓ Verified
Current Version
e8d4232b64b8ba5af552957124ce940883a096167698e60f41833e3c32aa058e
September 1, 2026 01:28 UTC
✓ Verified
Change Detected
September 1, 2026 01:28 UTC
Analysis Methodology
✓ Verified
Source Document
https://openrouter.ai/privacy
Citation Record
Entity: OpenRouter
Document: OpenRouter Privacy Policy
Record ID: CA-C-004769
Captured: 2026-09-01 01:28:21 UTC
URL: https://conductatlas.com/change/2026-09-01-openrouter-openrouter-privacy-policy-4769/
Accessed: Sept. 2, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
For legal and compliance teams

Institutional Analysis

Assessment

OpenRouter raised its minimum age requirement from 13 to 18 and introduced detailed handling procedures for Files API features covering data retention, encryption, transmission, and use limitations. This change engages COPPA compliance considerations (age eligibility), …

🔒 Full institutional analysis

Regulatory exposure, obligation change, escalation trigger, board-ready language, and recommended action for legal and compliance teams.

Unlock the full institutional analysis — Insight

ConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-004769.

Full Changes

View complete diff →

Document Context

Version history → Policy drift analysis → Document page →
Document
OpenRouter Privacy Policy
Entity
OpenRouter
Captured
September 1, 2026
Source URL
https://openrouter.ai/privacy
Other changes to OpenRouter Privacy Policy
Previous change Aug 26, 2026
OpenRouter's privacy policy was updated to add the word 'Brand' to a navigation menu section in the footer. The change …
Low Neutral
View full version history →
More from OpenRouter
Sep 1, 2026 High
OpenRouter Terms of Service

OpenRouter raised the minimum age requirement from 13 to 18 years old, removed language allowing younger users with parental permission, …

Aug 26, 2026 Low
OpenRouter Privacy Policy

OpenRouter's privacy policy was updated to add the word 'Brand' to a navigation menu section in the footer. The change …

Aug 26, 2026 Low
OpenRouter Terms of Service

OpenRouter's Terms of Service was updated on August 26, 2026 to add the word 'Brand' to its footer navigation list. …

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Stay ahead of the changes

Track OpenRouter policy changes

Get alerted when this policy changes again, including what changed and why it matters.

All OpenRouter changes →