Users in the EU, EEA, and UK have rights under GDPR and UK GDPR to access, correct, delete, restrict processing of, and obtain a portable copy of their personal data held by OpenRouter.
This analysis describes what OpenRouter's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The policy acknowledges GDPR and UK GDPR rights for EEA and UK users but does not specify the lawful basis for processing under GDPR Article 6, which may be material for users or regulators assessing the adequacy of OpenRouter's data processing compliance.
Interpretive note: The policy does not specify the GDPR lawful basis for processing or international data transfer mechanisms, creating uncertainty about the completeness of GDPR compliance as disclosed.
Complete removal of GDPR rights disclosure for EEA and UK users eliminates transparency about statutory data protection rights in the main privacy policy document.
View full change record →EEA and UK users can contact OpenRouter to exercise data subject rights including access, rectification, erasure, and portability, and the policy states users may lodge complaints with their local data protection authority if they believe their rights have been violated.
How other platforms handle this
You may contact our privacy team with any requests of disclosure, correction, or deletion of your personal information. You may also request suspension of use or suspension of sharing of your personal information with certain third parties.
If you choose to reveal any personal information about yourself to other users, you do so at your own risk. We strongly encourage you to use caution in disclosing any personal information online.
When you are asked to provide information, you may decline to do so; but if you choose not to provide information that is necessary to provide some of our Services, you may not be able to use those Services.
"If you are located in the European Economic Area or the United Kingdom, you have certain rights under applicable data protection law. These may include the right to (i) request access and obtain a copy of your personal data, (ii) request rectification or erasure; (iii) object to or restrict processing of your personal data; and (iv) portability of your personal data.Excerpt from OpenRouter's Privacy Policy
1.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The policy acknowledges GDPR and UK GDPR rights for EEA and UK users but does not specify the lawful basis for processing under GDPR Article 6, which may be material for users or regulators assessing the adequacy of OpenRouter's data processing compliance.
EEA and UK users can contact OpenRouter to exercise data subject rights including access, rectification, erasure, and portability, and the policy states users may lodge complaints with their local data protection authority if they believe their rights have been violated.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenRouter.