Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does OpenRouter Work in China? Prompts, the Generative-AI Filing & a Layered Cross-Border Transfer

OpenRouter is reachable from the mainland but US-hosted with no China region — and every call crosses the border to OpenRouter first, then forwards your prompts on to whichever upstream model provider serves the model. A compliance-first look at the layered PIPL cross-border transfer, the CAC generative-AI filing gate, and the lawful China AI path.

Does OpenRouter work in China?

OpenRouter is reachable from the mainland, but it is US-hosted with no China region — so every call is a cross-border transfer, and the real question is compliance, not speed.

OpenRouter does not host the models; it forwards your request to whichever upstream provider serves the model, so your prompts, documents, uploaded files, and the code and personal data inside them cross the border to OpenRouter first and then onward to a provider in a jurisdiction you don't control. That is a layered PIPL cross-border transfer (Art 38–40), and a public mainland gen-AI feature also needs a CAC generative-AI filing — choosing a zero-retention or "does not train" provider cuts what is kept, not that the data crosses the border.

This is a risk map, not a ruling — settle specifics with counsel. Our China team can map your exposure →

What OpenRouter's own documentation says about China

FactPrimary source
OpenRouter is US-hosted and forwards your prompts onward to upstream model providers. Its Privacy Policy states that "your personal data may be transferred to our servers in the US, or to other countries outside the European Economic Area," and that "those Inputs are transmitted to the Model Provider you select, or that is selected through automatic routing" — so a mainland user's prompt crosses the border to OpenRouter and then on to a provider you don't directly control. This is a layered PIPL cross-border transfer. OpenRouter, "Privacy Policy" (§1, §3, §9), retrieved 2026-10-10
OpenRouter's own in-region routing covers only the EU and US — there is no China region, and training-use varies per upstream endpoint. Its docs state: "On the Business and Enterprise plans, OpenRouter supports in-region routing in the EU and US," and its provider table (retrieved 2026-10-10) marks retention from "Zero retention" through fixed windows to "Prompts are retained for unknown period," with several providers flagged as able to train on prompts. OpenRouter also notes it "cannot control Model Provider-side training once user data is transmitted." OpenRouter Docs, "Provider Logging — Provider Data Retention Policies," retrieved 2026-10-10
A public generative-AI feature for mainland users needs a CAC filing. China's Interim Measures for the Management of Generative AI Services (生成式人工智能服务管理暂行办法, CAC, in force since Aug 15, 2023) govern services that generate content for the public within China's territory (Art 2), with a security assessment and algorithm filing for services able to shape public opinion (Art 17). The upstream API vendor files none of this for you; the duty attaches to the feature you operate. Interim Measures for the Management of Generative AI Services, CAC Order No. 15, Arts. 2 and 17 (cac.gov.cn), retrieved 2026-10-10
Prompts sent offshore are a PIPL cross-border transfer. Sending a Chinese user's prompts, uploaded files, or records to a model hosted outside the mainland triggers PIPL Articles 38–40: notice, a separate consent, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. Choosing a zero-retention or "does not train" provider reduces what is kept, not that the data crosses the border. Personal Information Protection Law of the PRC, Articles 38–40 (cac.gov.cn), retrieved 2026-10-10

Sources verified by the 21YunBox compliance team on 2026-10-10.

Before anyone measures how quickly OpenRouter answers from Shanghai, the question that settles it for a mainland-China product is plainer: may your users’ prompts lawfully leave the country, and does the public AI feature you are building need a filing with the Cyberspace Administration of China? OpenRouter is reachable from the mainland and US-hosted — there is no China region to select, and its own in-region routing covers only the EU and US. It is not a model host: it is a unified API that forwards each request to whichever upstream provider serves the model, so what you send it — prompts, conversation context, retrieved documents, uploaded files, and the source code, credentials, and personal details inside them — crosses the border to OpenRouter first, then onward to a provider in a jurisdiction and under a data policy you do not control. That is personal information, and often trade secrets, moving offshore in two hops.

OpenRouter's Privacy Policy, section 9 'Data Transfers,' stating that a user's personal data may be transferred to OpenRouter's servers in the US or to other countries outside the European Economic Area, alongside its statement that Inputs are transmitted to the Model Provider selected or chosen by automatic routing
OpenRouter's Privacy Policy states that "your personal data may be transferred to our servers in the US, or to other countries outside the European Economic Area" — and those US servers are only the first stop, because OpenRouter then forwards each request on to the upstream model provider that serves it. Source: openrouter.ai/privacy

OpenRouter in China at a glance

What decides it In OpenRouter's own terms — and China's law
Where inference runs OpenRouter is US-hosted and does not run the models itself — it forwards each request to the upstream Model Provider you select, "or that is selected through automatic routing." Its own in-region routing is limited to the EU and US; there is no mainland-China region to choose.
What you send it — and why it is PI Prompts, conversation context, retrieved documents, uploaded files, and generated image/audio/video — plus the names, contact details, IDs, financial or health data, source code, and secrets inside them. That is personal information under PIPL; the voice- and face-processing features OpenRouter documents are biometric data (PIPL Art 28 sensitive PI), and code and internal documents are frequently trade secrets.
Your China users' prompts = a cross-border transfer Sending a mainland user's Inputs to OpenRouter's offshore servers, and onward to the provider, is a cross-border transfer of personal information under PIPL (Articles 38–40): notice, a separate consent, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. The layering adds a second hop, not a safe harbor.
The generative-AI filing gate A public-facing generative-AI feature for mainland users turns on China's Interim Measures for the Management of Generative AI Services (生成式人工智能服务管理暂行办法, CAC, in force Aug 15, 2023) — content-safety duties, AI-content labeling, and filing for services able to shape public opinion. Because OpenRouter picks the endpoint for you, the routing and selection behavior may also touch the Algorithm Recommendation Provisions. OpenRouter files none of this for you.
Reachability is not the axis That a call completes from Beijing settles nothing. The China-facing app or chat UI that carries the feature is itself a public mainland service — it needs an ICP filing (备案) and compliant in-country delivery, which an offshore API gives it no footing for.

No mainland region, so your prompts and data leave the country

OpenRouter sets this out in its own policy. Its Privacy Policy states that “your personal data may be transferred to our servers in the US, or to other countries outside the European Economic Area,” and those servers are the first stop, not the last: “those Inputs are transmitted to the Model Provider you select, or that is selected through automatic routing.” OpenRouter does not run the models. It is a router that forwards each call to an upstream provider, which means a mainland user’s prompt makes two offshore hops — to OpenRouter, then to a provider whose location and data terms you do not control and that differ from one endpoint to the next. OpenRouter’s documentation confirms there is no mainland footing: “On the Business and Enterprise plans, OpenRouter supports in-region routing in the EU and US,” so that prompts and completions “are processed within that region and do not leave it” — a feature that exists only for the EU and the US. There is no China region on that list.

It is worth being precise about one thing a reader might hope closes the gap. OpenRouter’s routing table does include China-brand endpoints — Alibaba Cloud Int., Baidu Qianfan, Tencent Cloud, and DeepSeek among them. Selecting one does not make this a China deployment. The request still transits OpenRouter’s offshore US edge before it reaches that provider, so it remains a cross-border transfer, and it does nothing to file your public feature or to give your China-facing surface an ICP filing. Reaching a Chinese model through an offshore router is not the same as standing one up lawfully inside China.

What you send it is personal information

A prompt is rarely just a question. Through OpenRouter it carries whatever your users and your app put in front of the model: names, contact details, order and account records, uploaded PDFs and images, retrieved documents, and — for AI coding and agent features — source code together with the API keys, tokens, and credentials embedded in it. Routed from a user in China to a model hosted offshore, that is a transfer of personal information under China’s Personal Information Protection Law. Some of it is sensitive personal information under PIPL Article 28: government IDs, financial or health details, anything concerning minors — and, by OpenRouter’s own description, the voice and face data behind its “voice cloning,” “speaker identification,” and “face cloning” features, which it treats as biometric data. Source code and internal documents are, on top of that, routinely trade secrets.

The training-use picture varies by endpoint, and OpenRouter is candid about it. Its policy says “Some Model Providers may use your Inputs and Outputs for model training or improvement,” while “OpenRouter does not use your Inputs or Outputs for model training,” and that if “you opt out of training in your account settings, OpenRouter will not route to providers that train.” Its provider table, retrieved October 10, 2026, marks each endpoint’s handling — retention from “Zero retention” through fixed windows (Anthropic and Mistral at 30 days, Google AI Studio at 55 days) to “Prompts are retained for unknown period,” with several providers, DeepSeek among them, flagged as able to train on prompts. But OpenRouter also states the limit of its own controls: “OpenRouter cannot control Model Provider-side training once user data is transmitted.” Opting out of training, or pinning to a zero-retention endpoint, changes what a provider keeps or learns. It does not change that the data left the mainland.

The filing gate — and why trimming retention doesn’t close the door

Suppose you still want a chat box, a “summarize this” button, or an agent in a product aimed at mainland users. The first gate is not which model sits behind it but whether you may offer a public-facing generative-AI service in China at all. China’s Interim Measures for the Management of Generative AI Services (生成式人工智能服务管理暂行办法, Cyberspace Administration of China, in force since August 15, 2023) govern providing generative content “to the public within the territory of the People’s Republic of China,” and attach duties on training data, content safety, personal-information handling, and labeling of AI-generated content — with a security assessment and algorithm filing for services able to shape public opinion. Because OpenRouter chooses the upstream endpoint for you, the automatic routing and selection behavior can also bring the Algorithm Recommendation Provisions into scope. None of these filings travel with the API: a provider that does not serve the mainland files nothing on your behalf, and the duty attaches to the public feature you operate.

This is why the privacy levers OpenRouter offers — a zero-retention endpoint, a “does not train” provider, EU or US in-region routing — are useful but do not answer the China question. They reduce what crosses and what is kept; they do not change that your mainland users’ personal information crosses the border, and they leave the generative-AI filing duty and the data-residency question untouched. Where your organization is a critical information infrastructure operator or a large-volume handler, an in-country storage duty also applies — PIPL Article 40, read with Cybersecurity Law Article 39 (formerly Article 37); the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, with the substance unchanged — and a model reached offshore structurally cannot meet it. This page maps exposure; it is not a ruling. Where the lines fall for your specific entity, data, and users is a question to settle with qualified China counsel against what you actually ship.

The lawful path — map, localize, deliver

There is a lawful way to put generative AI in front of Chinese users, and it does not run around OpenRouter’s offshore boundary — it replaces the call that cannot lawfully be served offshore with one that can. 21YunBox works it in three moves. We map your exposure: the PIPL cross-border transfer, the generative-AI filing and algorithm-filing duties, the sensitive-PI and trade-secret surface in what you send the model, and the ICP filing your China-facing property carries. We localize: stand up a lawful China-legal model path — a CAC-filed domestic model or an in-China sovereign-cloud offering operated by a licensed local operator — and integrate it in place of the offshore OpenRouter call, keeping consented, in-country processing for what must stay on mainland soil. That is not a route to the offshore endpoint, and it is not the same as selecting a China-brand model through OpenRouter’s offshore router. And we deliver the China-facing surface — the app, the chat UI, the API edge your mainland users hit — over ICP-filed, in-country infrastructure, the 21YunBox Optimizer, sitting in front of the stack you already run, with no rebuild and no second codebase.

The result is a generative-AI feature that runs legally and compliantly for your users in China. 21YunBox is a compliant overlay, not a migration, and a partner to the tools you already use, not a competitor to them. 21YunBox never uses or suggests circumvention of any kind.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Is OpenRouter available in mainland China?
OpenRouter is reachable from the mainland and US-hosted, but there is no China region to select — its own in-region routing covers only the EU and US. So reachability is not the real question: every call sends your users' prompts across the border, and OpenRouter then forwards them on to an upstream provider, making each request a PIPL cross-border transfer. Treat the specifics as a risk to confirm with counsel.
Does choosing a zero-retention or "does not train" provider make OpenRouter compliant for China?
No. Those controls reduce what an upstream provider keeps or learns from your data; they do not change that your mainland users' personal information leaves the country, and they leave the generative-AI filing duty and the data-residency question untouched. OpenRouter itself states it "cannot control Model Provider-side training once user data is transmitted." The cross-border transfer and the CAC filing for a public feature still have to be addressed.
Can I legally offer an OpenRouter-powered feature to users in China?
Offering a public-facing generative-AI feature inside the mainland turns on a CAC filing under the Interim Measures for the Management of Generative AI Services (in force since Aug 15, 2023), and the automatic routing and selection behavior may also touch the Algorithm Recommendation Provisions — while any prompts sent to a model hosted offshore are a PIPL cross-border transfer. OpenRouter files none of this for you. The lawful path is a CAC-filed domestic or in-China sovereign-cloud model, surfaced through an ICP-filed, in-country delivery layer. 21YunBox maps that path, localizes your feature onto it, and delivers it in-country; confirm your exact obligations with counsel.

ARTICLES RELATED TO OPENROUTER

CATEGORIES

AI and ML

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.