10 Total
1 High severity
8 Medium severity
1 Low severity
Summary

This is OpenRouter's privacy policy, which explains how the company collects and uses personal data when you use its AI model routing platform at openrouter.ai. The policy states that OpenRouter collects your account information, payment and Credits transaction details, browsing activity, IP address, location data, and any text you enter into the service, and may share that data with service providers, analytics partners, and advertising vendors. If you are a California resident or based in the EU or UK, the policy describes specific rights you have to access, delete, or opt out of the sharing of your personal data, which you can exercise by emailing privacy@openrouter.ai.

Technical / Legal Breakdown

This document is OpenRouter, Inc.'s Privacy Policy, last updated April 15, 2025, governing personal data collected through the openrouter.ai website, the OpenRouter API service, and third-party applications linking to this policy; the stated legal basis for collection is user consent established by continued use of the site or service. The policy states that OpenRouter collects name, mailing address, email address, telephone number, user Inputs to the service, transaction and Credits purchase details, IP address, operating system, browser type, location data, browsing history, search queries, and data from third-party business partners; it also states that collected data may be shared with service providers, business partners, advertising and analytics vendors, and in connection with corporate transactions such as mergers or asset sales. A notable provision discloses that OpenRouter does not control how downstream LLM providers handle user Inputs or Outputs, including for model training purposes, and directs users to review individual provider terms; the policy also reserves the right to modify its terms at any time without prior notice, with changes applying retroactively to existing data, though material changes will be communicated to registered users by email. The policy references compliance with CCPA for California residents, granting rights to know, delete, and opt out of data sale or sharing, and acknowledges GDPR-framework rights for users in the European Economic Area and UK; the document does not specify a GDPR legal basis beyond consent, and the adequacy of consent mechanisms for EU and UK users under GDPR Articles 6 and 7 may require further evaluation depending on how consent is operationalized in practice.

Institutional Analysis

Institutional analysis available with Professional

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.

Start Professional free trial
High — 1 provision
Medium — 8 provisions
Low — 1 provision

Monitoring

OpenRouter has updated this document before.

Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →

Professional Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Professional free trial

Cross-platform context

See how other platforms handle Disclaimer of Responsibility for LLM Provider Handling of User Inputs and similar clauses.

Compare across platforms →
Archival ProvenanceSource & Archival Record
Last Captured May 13, 2026 01:24 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000811
Version ID CA-V-002561
SHA-256 ff13364032319c3e8eda9da3096e416fbabad02f54c72652f3951ce9f5411961
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans