Provision record
OpenRouter · OpenRouter Terms of Service · View original document ↗

Organizational Account Admin Control Over Logging and Training

High severity Medium confidence Explicit document language Common · 290 of 352 platforms
Stay ahead of the changes
Track OpenRouter and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
Document Record

What it is

When using OpenRouter through an employer's or organization's account, your prompts, chats, and data may be logged or used for model training if your organization's administrator has enabled those settings, potentially without you receiving separate notice.

This analysis describes what OpenRouter's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

The terms establish that Admin Users can enable prompt logging, chat logging, and model training for all Authorized Users in their organization; individual Authorized Users may not have independent visibility into or control over these configurations.

Interpretive note: The document does not specify what disclosures OpenRouter provides directly to Authorized Users about active logging or training configurations, creating uncertainty about whether platform-level notice satisfies applicable transparency obligations.

Recent Activity

This document changed recently

Medium Aug 5, 2026

The updated terms establish that users are responsible for all account activity and charges occurring under their API credentials, with the exception of activity directly caused by OpenRouter's breach of the terms. Users are required to promptly notify OpenRouter of any actual or suspected compromise or unauthorized use of API credentials. OpenRouter reserves the right to suspend, revoke, or limit API credentials or account access if OpenRouter reasonably believes doing so is necessary to protect the service, the user, OpenRouter, or any third party. Additionally, promotional credits provided by OpenRouter have no cash value, cannot be refunded or exchanged except under specific conditions, are non-transferable between accounts, and expire on dates specified at issuance or in accordance with the terms. You can manage your API credentials through your account settings and should promptly contact OpenRouter if you suspect unauthorized access.

View change record →
Medium Jul 7, 2026

The updated terms clarify that enabling prompt logging automatically activates chat logging as well, and grant OpenRouter a perpetual, worldwide license to use your content for service provision and commercial purposes. This includes the explicit right to license or sell your user content in anonymized form. Users accessing Stealth Program models must now also agree to a separate End User License Agreement. You can disable prompt logging in your account settings if you do not wish to grant these permissions.

View change record →

Clause Stability Stable

0
Changes
3
Months Monitored
May 12, 2026
First Seen
May 20, 2026
Last Seen
This clause type exists across 5149 other provisions on other platforms.

Consumer impact (what this means for users)

Authorized Users in organizational accounts may have their prompts and conversations logged and potentially used for model training based on configurations set by their organization's Admin User, without necessarily receiving separate consent requests from OpenRouter directly.

How other platforms handle this

Google Cloud Medium

You and your organization's administrator can access several types of Service Data directly from Google Cloud, including your account information, billing contact information, payment and transaction information, as well as product and communication settings and configurations.

Notion Medium

If you registered to use Notion's Services with such an email address, but you do not use the Services in connection with your organization...you may transfer your account to a different email address.

Tinder Medium

If you choose to reveal any personal information about yourself to other users, you do so at your own risk. We strongly encourage you to use caution in disclosing any personal information online.

See all platforms with this clause type →
▸ View Original Clause Language DOCUMENT RECORD
"
The Service allows creation of two account types: organizational accounts and individual accounts. An organizational account is managed by an administrative user ("Admin User") who can invite individuals from the Admin User's organization ("Authorized Users") to the organizational account. Authorized Users may only use the Service as configured by the Admin User, with such configurations which may include, without limitation, enabling prompt logging, chat logging, zero data retention, model training, and other settings.

Excerpt from OpenRouter's Terms of Service

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

(1) REGULATORY LANDSCAPE: This provision creates a layered data processing relationship that may engage GDPR Articles 13 and 14 (transparency obligations toward data subjects), CCPA disclosure requirements, and applicable employment privacy laws in EU member …

Insight

Unlock the full institutional analysis

Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.

Applicable agencies

  • Federal Trade Commission (ftc)
    Oversees unfair or deceptive business practices and can investigate companies that mislead consumers about data collection, sharing, or use.
    Who can file: Anyone affected by the company's practices (US or international)
    What you need: Your account details, a timeline of relevant events, and a description of the specific issue
    What to expect: Complaints inform FTC enforcement priorities and investigations but do not result in individual resolution or compensation
    File a complaint →
  • State Attorney General
    State AGs in California, New York, Texas, and other states can investigate violations of state consumer protection and privacy laws, including CCPA (California), SHIELD Act (New York), and equivalents.
    Who can file: Residents of states with comprehensive privacy laws — primarily California, Virginia, Colorado, Connecticut, and Utah
    What you need: Evidence of the violation, explanation of how your state rights were affected, and your account or contact information with the company
    What to expect: Outcomes vary by state. May result in investigation, enforcement action, or requirement for the company to change practices. No direct individual compensation in most cases.

    Search "[your state] attorney general consumer complaint" to find your state's direct complaint form

Applicable regulations

Colorado AI Act
US-CO
Connecticut Data Privacy Act Amendments
US-CT
EU AI Act - High Risk Provisions
EU
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
OpenRouter Terms of Service
Entity
OpenRouter
Document last updated
May 12, 2026
Tracking information
First tracked
May 12, 2026
Last verified
May 12, 2026
Record ID
CA-P-011891
Document ID
CA-D-00810
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
3b6f88e048a976fcb3beebb8fa5d94c8398d1eee6eb5924035105dab83cb5b1e
Analysis generated
May 12, 2026 16:00 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: OpenRouter
Document: OpenRouter Terms of Service
Record ID: CA-P-011891
Captured: 2026-05-12 16:00:19 UTC
SHA-256: 3b6f88e048a976fc…
URL: https://conductatlas.com/platform/openrouter/openrouter-terms-of-service/provision/CA-P-011891/organizational-account-admin-control-over-logging-and-training/
Accessed: Aug. 26, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Related Analysis

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does OpenRouter's Organizational Account Admin Control Over Logging and Training clause do?

The terms establish that Admin Users can enable prompt logging, chat logging, and model training for all Authorized Users in their organization; individual Authorized Users may not have independent visibility into or control over these configurations.

How does this clause affect you?

Authorized Users in organizational accounts may have their prompts and conversations logged and potentially used for model training based on configurations set by their organization's Admin User, without necessarily receiving separate consent requests from OpenRouter directly.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.

Is ConductAtlas affiliated with OpenRouter?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenRouter.