OpenRouter · OpenRouter Terms of Service · View original document ↗

Organizational Admin User Data Configuration

High severity Medium confidence Explicitdocumentlanguage Unique · 0 of 343 platforms
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity OpenRouter recorded 4 documented changes in the last 30 days.
Start monitoring updates
Monitor governance changes for OpenRouter Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

The agreement establishes that organizational accounts are controlled by an Admin User who configures service settings for all Authorized Users within the organization, including enabling or disabling prompt logging, chat logging, zero data retention, and model training at the organizational level.

This analysis describes what OpenRouter's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision delegates data handling configuration, including prompt logging and model training enablement, to organizational Admin Users rather than to individual Authorized Users. The data handling posture of Authorized Users, including whether their prompts are logged or used for model training, is determined by Admin User settings rather than individual consent.

Interpretive note: The terms do not specify whether OpenRouter acts as a data processor or controller for organizational prompt data, and the legal obligations flowing from Admin User configuration choices depend on applicable jurisdiction and data protection framework.

Consumer impact (what this means for users)

Under this clause, Authorized Users operating under an organizational account have their prompt logging, chat logging, and model training settings determined by the Admin User's configuration rather than their own preferences. Individual Authorized Users may also create separate individual accounts to access the service with independent settings.

How other platforms handle this

Ledger Medium

At Ledger, earning and maintaining our users' trust is a top priority. That's why we are deeply committed not only to protecting your privacy and securing your personal data, but also to being fully transparent about how we handle it.

Garmin Medium

If you are located in the European Economic Area, Switzerland, or the United Kingdom, you have the right to access, correct, or erase your personal data; the right to restrict or object to our processing of your personal data; the right to data portability; and, where our processing is based on your...

Strava Medium

We use information to enhance the quality, reliability, and/or accuracy of our AI Features by creating, developing, training, testing, improving, and maintaining AI and ML models run by Strava or our service providers. We use aggregated, de-identified data for this purpose. We also use personal info...

See all platforms with this clause type →

Monitoring

OpenRouter has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
The Service allows creation of two account types: organizational accounts and individual accounts. An organizational account is managed by an administrative user ("Admin User") who can invite individuals from the Admin User's organization ("Authorized Users") to the organizational account. Authorized Users may only use the Service as configured by the Admin User, with such configurations which may include, without limitation, enabling prompt logging, chat logging, zero data retention, model training, and other settings.

— Excerpt from OpenRouter's OpenRouter Terms of Service

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

1) REGULATORY LANDSCAPE: The delegation of prompt logging and model training configuration to Admin Users may engage GDPR Article 28 (processor obligations) and Article 29 (processing under the authority of the controller) for EU-resident users, as well as CCPA obligations for California residents whose prompts may be logged and used for model training. Employers enabling prompt logging for employee accounts may have additional obligations under applicable employment privacy laws. The EU AI Act may impose obligations on how training data is handled depending on model classification. 2) GOVERNANCE EXPOSURE: High for enterprise deployments. Organizations that deploy OpenRouter under organizational accounts and enable prompt logging or model training for Authorized Users bear responsibility for ensuring that this data handling is consistent with their privacy policies, employee agreements, and applicable data protection law. The broad configuration authority granted to Admin Users without described individual consent mechanisms creates compliance exposure for organizations in privacy-regulated jurisdictions. 3) JURISDICTION FLAGS: EU and EEA organizations face the highest exposure given GDPR requirements for lawful basis of processing and data subject rights. Illinois BIPA may be relevant if biometric data is processed, though this is unlikely in a text-based AI context. California CCPA creates disclosure and opt-out obligations if personal information in prompts is used for model training. 4) CONTRACT AND VENDOR IMPLICATIONS: Organizations should obtain a Data Processing Agreement from OpenRouter before enabling prompt logging or model training in organizational accounts, particularly for EU deployments. The terms do not describe whether OpenRouter acts as a processor or controller for organizational prompt data, which is a material gap for GDPR compliance assessments. Vendor due diligence should clarify OpenRouter's data processing role and sub-processor disclosures. 5) COMPLIANCE CONSIDERATIONS: Compliance teams should audit which Admin User configurations are active for their organizational accounts, particularly prompt logging and model training. Data protection impact assessments may be required for EU deployments where these features are enabled. Employee privacy notices should be reviewed to ensure they cover AI prompt data processing.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Monitor free for 14 days

Free: track 1 platform + weekly digest. Monitor: 25 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC has jurisdiction over data handling practices in consumer and commercial digital services, including undisclosed or inadequately disclosed data processing practices.
    File a complaint →
  • State AG
    State attorneys general in California and other jurisdictions with comprehensive privacy laws may have enforcement authority over organizational data handling practices involving personal information in AI prompt logs.
    File a complaint →

Applicable regulations

Colorado AI Act
US-CO
Connecticut Data Privacy Act Amendments
US-CT
EU AI Act - High Risk Provisions
EU
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
OpenRouter Terms of Service
Entity
OpenRouter
Document last updated
May 12, 2026
Tracking information
First tracked
May 21, 2026
Last verified
May 21, 2026
Record ID
CA-P-012769
Document ID
CA-D-00810
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
d22aa40bd1da8ba43c39e2622b935e1df3d8acb5d7abfae7670c288b44c0e544
Analysis generated
May 21, 2026 01:17 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: OpenRouter
Document: OpenRouter Terms of Service
Record ID: CA-P-012769
Captured: 2026-05-21 01:17:28 UTC
SHA-256: d22aa40bd1da8ba4…
URL: https://conductatlas.com/platform/openrouter/openrouter-terms-of-service/organizational-admin-user-data-configuration/
Accessed: June 8, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Compliance free trial

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does OpenRouter's Organizational Admin User Data Configuration clause do?

This provision delegates data handling configuration, including prompt logging and model training enablement, to organizational Admin Users rather than to individual Authorized Users. The data handling posture of Authorized Users, including whether their prompts are logged or used for model training, is determined by Admin User settings rather than individual consent.

How does this clause affect you?

Under this clause, Authorized Users operating under an organizational account have their prompt logging, chat logging, and model training settings determined by the Admin User's configuration rather than their own preferences. Individual Authorized Users may also create separate individual accounts to access the service with independent settings.

Is ConductAtlas affiliated with OpenRouter?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenRouter.