When using OpenRouter through an employer's or organization's account, your prompts, chats, and data may be logged or used for model training if your organization's administrator has enabled those settings, potentially without you receiving separate notice.
This analysis describes what OpenRouter's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The terms establish that Admin Users can enable prompt logging, chat logging, and model training for all Authorized Users in their organization; individual Authorized Users may not have independent visibility into or control over these configurations.
Interpretive note: The document does not specify what disclosures OpenRouter provides directly to Authorized Users about active logging or training configurations, creating uncertainty about whether platform-level notice satisfies applicable transparency obligations.
The updated terms establish that users are responsible for all account activity and charges occurring under their API credentials, with the exception of activity directly caused by OpenRouter's breach of the terms. Users are required to promptly notify OpenRouter of any actual or suspected compromise or unauthorized use of API credentials. OpenRouter reserves the right to suspend, revoke, or limit API credentials or account access if OpenRouter reasonably believes doing so is necessary to protect the service, the user, OpenRouter, or any third party. Additionally, promotional credits provided by OpenRouter have no cash value, cannot be refunded or exchanged except under specific conditions, are non-transferable between accounts, and expire on dates specified at issuance or in accordance with the terms. You can manage your API credentials through your account settings and should promptly contact OpenRouter if you suspect unauthorized access.
View change record →The updated terms clarify that enabling prompt logging automatically activates chat logging as well, and grant OpenRouter a perpetual, worldwide license to use your content for service provision and commercial purposes. This includes the explicit right to license or sell your user content in anonymized form. Users accessing Stealth Program models must now also agree to a separate End User License Agreement. You can disable prompt logging in your account settings if you do not wish to grant these permissions.
View change record →Authorized Users in organizational accounts may have their prompts and conversations logged and potentially used for model training based on configurations set by their organization's Admin User, without necessarily receiving separate consent requests from OpenRouter directly.
How other platforms handle this
You and your organization's administrator can access several types of Service Data directly from Google Cloud, including your account information, billing contact information, payment and transaction information, as well as product and communication settings and configurations.
If you registered to use Notion's Services with such an email address, but you do not use the Services in connection with your organization...you may transfer your account to a different email address.
If you choose to reveal any personal information about yourself to other users, you do so at your own risk. We strongly encourage you to use caution in disclosing any personal information online.
"The Service allows creation of two account types: organizational accounts and individual accounts. An organizational account is managed by an administrative user ("Admin User") who can invite individuals from the Admin User's organization ("Authorized Users") to the organizational account. Authorized Users may only use the Service as configured by the Admin User, with such configurations which may include, without limitation, enabling prompt logging, chat logging, zero data retention, model training, and other settings.Excerpt from OpenRouter's Terms of Service
(1) REGULATORY LANDSCAPE: This provision creates a layered data processing relationship that may engage GDPR Articles 13 and 14 (transparency obligations toward data subjects), CCPA disclosure requirements, and applicable employment privacy laws in EU member …
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Search "[your state] attorney general consumer complaint" to find your state's direct complaint form
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The terms establish that Admin Users can enable prompt logging, chat logging, and model training for all Authorized Users in their organization; individual Authorized Users may not have independent visibility into or control over these configurations.
Authorized Users in organizational accounts may have their prompts and conversations logged and potentially used for model training based on configurations set by their organization's Admin User, without necessarily receiving separate consent requests from OpenRouter directly.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenRouter.