The agreement establishes that organizational accounts are controlled by an Admin User who configures service settings for all Authorized Users within the organization, including enabling or disabling prompt logging, chat logging, zero data retention, and model training at the organizational level.
This analysis describes what OpenRouter's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision delegates data handling configuration, including prompt logging and model training enablement, to organizational Admin Users rather than to individual Authorized Users. The data handling posture of Authorized Users, including whether their prompts are logged or used for model training, is determined by Admin User settings rather than individual consent.
Interpretive note: The terms do not specify whether OpenRouter acts as a data processor or controller for organizational prompt data, and the legal obligations flowing from Admin User configuration choices depend on applicable jurisdiction and data protection framework.
The updated terms establish that users are responsible for all account activity and charges occurring under their API credentials, with the exception of activity directly caused by OpenRouter's breach of the terms. Users are required to promptly notify OpenRouter of any actual or suspected compromise or unauthorized use of API credentials. OpenRouter reserves the right to suspend, revoke, or limit API credentials or account access if OpenRouter reasonably believes doing so is necessary to protect the service, the user, OpenRouter, or any third party. Additionally, promotional credits provided by OpenRouter have no cash value, cannot be refunded or exchanged except under specific conditions, are non-transferable between accounts, and expire on dates specified at issuance or in accordance with the terms. You can manage your API credentials through your account settings and should promptly contact OpenRouter if you suspect unauthorized access.
View change record →The updated terms clarify that enabling prompt logging automatically activates chat logging as well, and grant OpenRouter a perpetual, worldwide license to use your content for service provision and commercial purposes. This includes the explicit right to license or sell your user content in anonymized form. Users accessing Stealth Program models must now also agree to a separate End User License Agreement. You can disable prompt logging in your account settings if you do not wish to grant these permissions.
View change record →Under this clause, Authorized Users operating under an organizational account have their prompt logging, chat logging, and model training settings determined by the Admin User's configuration rather than their own preferences. Individual Authorized Users may also create separate individual accounts to access the service with independent settings.
How other platforms handle this
If you choose to reveal any personal information about yourself to other users, you do so at your own risk. We strongly encourage you to use caution in disclosing any personal information online.
When you are asked to provide information, you may decline to do so; but if you choose not to provide information that is necessary to provide some of our Services, you may not be able to use those Services.
to request that your data be transferred to a third party (data portability)
"The Service allows creation of two account types: organizational accounts and individual accounts. An organizational account is managed by an administrative user ("Admin User") who can invite individuals from the Admin User's organization ("Authorized Users") to the organizational account. Authorized Users may only use the Service as configured by the Admin User, with such configurations which may include, without limitation, enabling prompt logging, chat logging, zero data retention, model training, and other settings.Excerpt from OpenRouter's Terms of Service
1) REGULATORY LANDSCAPE: The delegation of prompt logging and model training configuration to Admin Users may engage GDPR Article 28 (processor obligations) and Article 29 (processing under the authority of the controller) for EU-resident users, …
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Search "[your state] attorney general consumer complaint" to find your state's direct complaint form
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision delegates data handling configuration, including prompt logging and model training enablement, to organizational Admin Users rather than to individual Authorized Users. The data handling posture of Authorized Users, including whether their prompts are logged or used for model training, is determined by Admin User settings rather than individual consent.
Under this clause, Authorized Users operating under an organizational account have their prompt logging, chat logging, and model training settings determined by the Admin User's configuration rather than their own preferences. Individual Authorized Users may also create separate individual accounts to access the service with independent settings.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenRouter.