The policy authorizes disclosure of user personal data to third parties in connection with corporate transactions including mergers, asset sales, financing events, or acquisitions, including during negotiation phases.
This analysis describes what OpenRouter's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that personal data may be transferred to prospective acquirers or transaction counterparties prior to completion of a corporate transaction, without individualized user consent at the time of transfer.
Language simplified and narrowed: previous version detailed specific scenarios (bankruptcy, receivership, asset transition) and mentioned 'sold or transferred,' while current version uses more general 'share' language and removes references to bankruptcy and service transitions.
View full change record →Under this clause, personal data including account information, transaction history, and behavioral data may be disclosed to third parties during due diligence or financing processes, and may transfer to a new controlling entity upon completion of an acquisition or asset sale.
How other platforms handle this
We will also provide an individual opt-out choice, or opt-in for sensitive data, before we share your data with third parties other than our agents, or before we use it for a purpose other than which it was originally collected.
to request that your data be transferred to a third party (data portability)
Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.
"We may share your personal data in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.Excerpt from OpenRouter's Privacy Policy
REGULATORY LANDSCAPE: GDPR requires that data transfers in connection with corporate transactions maintain a lawful basis and that data subjects be informed of changes to the controller's identity.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes that personal data may be transferred to prospective acquirers or transaction counterparties prior to completion of a corporate transaction, without individualized user consent at the time of transfer.
Under this clause, personal data including account information, transaction history, and behavioral data may be disclosed to third parties during due diligence or financing processes, and may transfer to a new controlling entity upon completion of an acquisition or asset sale.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenRouter.