OpenRouter · OpenRouter Privacy Policy · View original document ↗

User Inputs Collected as Personal Data

Medium severity Medium confidence Explicitdocumentlanguage Unique · 0 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for OpenRouter Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

Text or data you type into the OpenRouter service that contains personal information is collected by OpenRouter, subject to the handling rules described in the Terms of Service for prompts.

This analysis describes what OpenRouter's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

The policy states that Inputs containing personal data are collected by OpenRouter, which means content submitted through the service interface, such as names, contact details, or other identifiable information embedded in messages, is subject to OpenRouter's data collection and sharing practices.

Interpretive note: The scope of what constitutes an 'Input' versus a 'prompt' governed by ToS section 5 is not fully clarified in the policy text, creating some ambiguity about which user-submitted content is subject to each set of rules.

Consumer impact (what this means for users)

Any personal information you include in text or data submitted through the OpenRouter service may be collected and retained by OpenRouter under this policy, in addition to being transmitted to the downstream AI model provider handling the request.

Cross-platform context

See how other platforms handle User Inputs Collected as Personal Data and similar clauses.

Compare across platforms →

Monitoring

OpenRouter has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Any text or data (excluding prompts you send to the Service, which are governed by section five of the Terms of Service section 5) you input into the Service ("Inputs") that include personal data will also be collected by us.

— Excerpt from OpenRouter's OpenRouter Privacy Policy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

1. REGULATORY LANDSCAPE: Collection of personal data embedded in user Inputs engages GDPR, CCPA, and other applicable privacy frameworks depending on user location. Where Inputs contain special categories of personal data under GDPR Article 9 (such as health information, biometric data, or political opinions), heightened processing restrictions apply. HIPAA may be relevant where Inputs contain protected health information. 2. GOVERNANCE EXPOSURE: High for enterprise and developer users who may be submitting third-party personal data through the API. The collection of Input data by OpenRouter, combined with the disclaimer of responsibility for downstream LLM provider handling, creates a dual data processing relationship that may require separate contractual and compliance analysis. 3. JURISDICTION FLAGS: EU and UK users face exposure where Inputs contain special category data under GDPR. US users processing health information face potential HIPAA implications. California users retain CCPA rights over Input data collected by OpenRouter. 4. CONTRACT AND VENDOR IMPLICATIONS: API users and developers should assess whether their application design results in users submitting personal data as Inputs, and should implement appropriate notices and consent mechanisms for their end users. Procurement teams should confirm that OpenRouter's DPA covers Input data collection. 5. COMPLIANCE CONSIDERATIONS: Developers building applications on the OpenRouter API should conduct a data flow analysis to identify whether end-user Inputs will contain personal data, and should ensure appropriate disclosures are made to their own users. Where Inputs may contain sensitive categories of data, a data protection impact assessment may be warranted.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Watcher free for 14 days

Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC has jurisdiction over data collection practices, including collection of personal data embedded in user-generated content submitted to online services.
    File a complaint →

Provision details

Document information
Document
OpenRouter Privacy Policy
Entity
OpenRouter
Document last updated
May 12, 2026
Tracking information
First tracked
May 12, 2026
Last verified
May 12, 2026
Record ID
CA-P-011905
Document ID
CA-D-00811
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
91717e659c28fa47150e1b31feba15f57c09644be2eb5595585f6bac16821776
Analysis generated
May 12, 2026 16:05 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: OpenRouter
Document: OpenRouter Privacy Policy
Record ID: CA-P-011905
Captured: 2026-05-12 16:05:01 UTC
SHA-256: 91717e659c28fa47…
URL: https://conductatlas.com/platform/openrouter/openrouter-privacy-policy/user-inputs-collected-as-personal-data/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does OpenRouter's User Inputs Collected as Personal Data clause do?

The policy states that Inputs containing personal data are collected by OpenRouter, which means content submitted through the service interface, such as names, contact details, or other identifiable information embedded in messages, is subject to OpenRouter's data collection and sharing practices.

How does this clause affect you?

Any personal information you include in text or data submitted through the OpenRouter service may be collected and retained by OpenRouter under this policy, in addition to being transmitted to the downstream AI model provider handling the request.

Is ConductAtlas affiliated with OpenRouter?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenRouter.