This analysis describes what OpenRouter's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The updated terms establish that users are responsible for all account activity and charges occurring under their API credentials, with the exception of activity directly caused by OpenRouter's breach of the terms. Users are required to promptly notify OpenRouter of any actual or suspected compromise or unauthorized use of API credentials. OpenRouter reserves the right to suspend, revoke, or limit API credentials or account access if OpenRouter reasonably believes doing so is necessary to protect the service, the user, OpenRouter, or any third party. Additionally, promotional credits provided by OpenRouter have no cash value, cannot be refunded or exchanged except under specific conditions, are non-transferable between accounts, and expire on dates specified at issuance or in accordance with the terms. You can manage your API credentials through your account settings and should promptly contact OpenRouter if you suspect unauthorized access.
View change record →The updated terms clarify that enabling prompt logging automatically activates chat logging as well, and grant OpenRouter a perpetual, worldwide license to use your content for service provision and commercial purposes. This includes the explicit right to license or sell your user content in anonymized form. Users accessing Stealth Program models must now also agree to a separate End User License Agreement. You can disable prompt logging in your account settings if you do not wish to grant these permissions.
View change record →How other platforms handle this
Affirm maintains physical, electronic and procedural security measures to guard against unauthorized access to systems and uses safeguards such as firewalls and data encryption.
Please recognize that protecting your Personal Data is also your responsibility. We urge you to take every precaution to protect your information when you are on the Internet...
These payment processors adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, Mastercard, American Express and Discover.
"The Receiving Party will use the same degree of care as to the Disclosing Party's Confidential Information that it uses to protect the confidentiality of its own confidential information of like kind (but in no event less than reasonable care).Excerpt from OpenRouter's Terms of Service
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The clause states: “The Receiving Party will use the same degree of care as to the Disclosing Party's Confidential Information that it uses to protect the confidentiality of its own confidential information of like kind (but in no event less than reasonable care).”
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenRouter.