For OpenRouter, you can setup an API key and limit it to only models that claim to not train on data, but that is just a claim. You can then use trust to judge which providers will honor that claim.
But if the data is really sensitive, you might want either a local model or a business subscription with some big name in the US that legally promises no data training.
So are we talking some app idea you are playing around with, or files filled with PHI/PII that you have legal mandates to safeguard? If the latter, I would stick to only provider with enterprise agreements to not store/train on the data. Even the ones who promise no training are likely storing the data for monitoring for abuse or such short term.
OpenRouter isn’t a provider, they route to other providers, so you would need to specify which ones you’re comfortable with anyway.
[1]:https://docs.fireworks.ai/guides/security_compliance/data_ha...
If it’s really sensitive then don’t use a cloud provider.