OpenRouter expanded its privacy policy to address file storage through a Files API feature, establishing how uploaded files like images, PDFs, and documents are handled, transmitted to model providers, encrypted, and retained until deletion or account closure. The policy also raised the minimum age requirement from 13 to 18 years old. These changes introduce detailed operational procedures for persistent file storage and clarify user eligibility.
Consumers: You must be at least 18 to use OpenRouter; younger users are no longer eligible.
Consumers: Files you upload are encrypted and OpenRouter staff cannot routinely access their contents.
Data controllers: When you delete files or close your account, OpenRouter will work to remove them from all systems within specified timeframes.
The updated policy raises the minimum age to use OpenRouter from 13 to 18 years old, meaning users under 18 are no longer eligible. For users who upload files through the Files API feature, the revised terms establish specific handling procedures: files are encrypted at rest and in transit, transmitted to model providers you select, retained until deletion or account closure, and not used for training or marketing purposes. The policy specifies that access is restricted to automated systems necessary to operate the service, and manual access occurs only for investigating violations, responding to legal process, or providing support. You can delete uploaded files at any time, which triggers removal efforts from active systems and backups within timeframes specified in the Data Processing Agreement.
→ If you are under 18 and currently use OpenRouter, review the updated policy to understand that your access may be restricted as of the effective date.
→ If you use the Files API to upload documents, you may delete files at any time through your account; deleted files will be removed from active systems and backups per OpenRouter's Data Processing Agreement.
Raised from 13 to 18 years old, excluding minors from platform access.
Establishes encryption, retention, deletion, and access control procedures for persistently uploaded files.
Explicitly states uploaded files are not used for model training, unrelated analytics, or marketing.
This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology
OpenRouter raised its minimum age requirement from 13 to 18 and introduced detailed handling procedures for Files API features covering data retention, encryption, transmission, and use limitations. This change engages COPPA compliance considerations (age eligibility), …
Regulatory exposure, obligation change, escalation trigger, board-ready language, and recommended action for legal and compliance teams.
Unlock the full institutional analysis — InsightConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-004769.
OpenRouter raised the minimum age requirement from 13 to 18 years old, removed language allowing younger users with parental permission, …
OpenRouter's privacy policy was updated to add the word 'Brand' to a navigation menu section in the footer. The change …
OpenRouter's Terms of Service was updated on August 26, 2026 to add the word 'Brand' to its footer navigation list. …
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
Get alerted when this policy changes again, including what changed and why it matters.