Provision record
OpenRouter · OpenRouter Terms of Service · View original document ↗

Organizational Admin User Data Configuration

High severity Medium confidence Explicit document language Common · 290 of 352 platforms
Stay ahead of the changes
Track OpenRouter and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
Document Record

What it is

The agreement establishes that organizational accounts are controlled by an Admin User who configures service settings for all Authorized Users within the organization, including enabling or disabling prompt logging, chat logging, zero data retention, and model training at the organizational level.

This analysis describes what OpenRouter's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision delegates data handling configuration, including prompt logging and model training enablement, to organizational Admin Users rather than to individual Authorized Users. The data handling posture of Authorized Users, including whether their prompts are logged or used for model training, is determined by Admin User settings rather than individual consent.

Interpretive note: The terms do not specify whether OpenRouter acts as a data processor or controller for organizational prompt data, and the legal obligations flowing from Admin User configuration choices depend on applicable jurisdiction and data protection framework.

Recent Activity

This document changed recently

Medium Aug 5, 2026

The updated terms establish that users are responsible for all account activity and charges occurring under their API credentials, with the exception of activity directly caused by OpenRouter's breach of the terms. Users are required to promptly notify OpenRouter of any actual or suspected compromise or unauthorized use of API credentials. OpenRouter reserves the right to suspend, revoke, or limit API credentials or account access if OpenRouter reasonably believes doing so is necessary to protect the service, the user, OpenRouter, or any third party. Additionally, promotional credits provided by OpenRouter have no cash value, cannot be refunded or exchanged except under specific conditions, are non-transferable between accounts, and expire on dates specified at issuance or in accordance with the terms. You can manage your API credentials through your account settings and should promptly contact OpenRouter if you suspect unauthorized access.

View change record →
Medium Jul 7, 2026

The updated terms clarify that enabling prompt logging automatically activates chat logging as well, and grant OpenRouter a perpetual, worldwide license to use your content for service provision and commercial purposes. This includes the explicit right to license or sell your user content in anonymized form. Users accessing Stealth Program models must now also agree to a separate End User License Agreement. You can disable prompt logging in your account settings if you do not wish to grant these permissions.

View change record →

Clause Stability Stable

0
Changes
3
Months Monitored
May 21, 2026
First Seen
May 22, 2026
Last Seen
This clause type exists across 5149 other provisions on other platforms.

Consumer impact (what this means for users)

Under this clause, Authorized Users operating under an organizational account have their prompt logging, chat logging, and model training settings determined by the Admin User's configuration rather than their own preferences. Individual Authorized Users may also create separate individual accounts to access the service with independent settings.

How other platforms handle this

Tinder Medium

If you choose to reveal any personal information about yourself to other users, you do so at your own risk. We strongly encourage you to use caution in disclosing any personal information online.

Skillshare Medium

When you are asked to provide information, you may decline to do so; but if you choose not to provide information that is necessary to provide some of our Services, you may not be able to use those Services.

Square Medium

to request that your data be transferred to a third party (data portability)

See all platforms with this clause type →
▸ View Original Clause Language DOCUMENT RECORD
"
The Service allows creation of two account types: organizational accounts and individual accounts. An organizational account is managed by an administrative user ("Admin User") who can invite individuals from the Admin User's organization ("Authorized Users") to the organizational account. Authorized Users may only use the Service as configured by the Admin User, with such configurations which may include, without limitation, enabling prompt logging, chat logging, zero data retention, model training, and other settings.

Excerpt from OpenRouter's Terms of Service

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1) REGULATORY LANDSCAPE: The delegation of prompt logging and model training configuration to Admin Users may engage GDPR Article 28 (processor obligations) and Article 29 (processing under the authority of the controller) for EU-resident users, …

Insight

Unlock the full institutional analysis

Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.

Applicable agencies

  • Federal Trade Commission (ftc)
    Oversees unfair or deceptive business practices and can investigate companies that mislead consumers about data collection, sharing, or use.
    Who can file: Anyone affected by the company's practices (US or international)
    What you need: Your account details, a timeline of relevant events, and a description of the specific issue
    What to expect: Complaints inform FTC enforcement priorities and investigations but do not result in individual resolution or compensation
    File a complaint →
  • State Attorney General
    State AGs in California, New York, Texas, and other states can investigate violations of state consumer protection and privacy laws, including CCPA (California), SHIELD Act (New York), and equivalents.
    Who can file: Residents of states with comprehensive privacy laws — primarily California, Virginia, Colorado, Connecticut, and Utah
    What you need: Evidence of the violation, explanation of how your state rights were affected, and your account or contact information with the company
    What to expect: Outcomes vary by state. May result in investigation, enforcement action, or requirement for the company to change practices. No direct individual compensation in most cases.

    Search "[your state] attorney general consumer complaint" to find your state's direct complaint form

Applicable regulations

Colorado AI Act
US-CO
Connecticut Data Privacy Act Amendments
US-CT
EU AI Act - High Risk Provisions
EU
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
OpenRouter Terms of Service
Entity
OpenRouter
Document last updated
May 12, 2026
Tracking information
First tracked
May 21, 2026
Last verified
May 21, 2026
Record ID
CA-P-012769
Document ID
CA-D-00810
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
d22aa40bd1da8ba43c39e2622b935e1df3d8acb5d7abfae7670c288b44c0e544
Analysis generated
May 21, 2026 01:17 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: OpenRouter
Document: OpenRouter Terms of Service
Record ID: CA-P-012769
Captured: 2026-05-21 01:17:28 UTC
SHA-256: d22aa40bd1da8ba4…
URL: https://conductatlas.com/platform/openrouter/openrouter-terms-of-service/provision/CA-P-012769/organizational-admin-user-data-configuration/
Accessed: Aug. 11, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Related Analysis

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does OpenRouter's Organizational Admin User Data Configuration clause do?

This provision delegates data handling configuration, including prompt logging and model training enablement, to organizational Admin Users rather than to individual Authorized Users. The data handling posture of Authorized Users, including whether their prompts are logged or used for model training, is determined by Admin User settings rather than individual consent.

How does this clause affect you?

Under this clause, Authorized Users operating under an organizational account have their prompt logging, chat logging, and model training settings determined by the Admin User's configuration rather than their own preferences. Individual Authorized Users may also create separate individual accounts to access the service with independent settings.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.

Is ConductAtlas affiliated with OpenRouter?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenRouter.