Privacy policy

The public page telling users what data you collect, why, who you share it with, and how they can get it back or deleted.

the legal page every site hasthe data blurb in the footerprivacy noticeprivacy statementdata protection noticeprivacy poilcythe page that says what data you collectthe GDPR page in the footer

See it

Live demo coming soon

What it is

A privacy policy is a disclosure, not a contract. Nobody negotiates it and nobody signs it: you publish it so people can find out what you collect, why you are allowed to collect it, who else touches it, how long you keep it, and how they get it back or deleted. GDPR articles 13 and 14 spell out the required contents, CCPA adds its own list, and both Apple and Google refuse app submissions without a live URL.

The usable version covers what articles 13 and 14 actually ask for: who you are and how to reach you, the categories of data collected, the purpose and lawful basis for each, the recipients or categories of recipients, retention periods, international transfers and the mechanism behind them, the rights users can exercise plus the address they exercise them at, the right to complain to a supervisory authority, where the data came from when you did not get it from the user, and any automated decision-making with legal or similarly significant effects. Naming your subprocessors outright is not universally required, but it is the version enterprise buyers and regulators like. Write it against your actual stack: open your vendor list and your network tab, then describe what is really there, and stamp it with a last-updated date.

Gotcha: generated templates lie in both directions. They claim data you never touch (fine until a regulator asks you to produce it) and they quietly omit the analytics, session-replay, and LLM vendors you added last quarter (not fine at all). Second gotcha: a privacy policy is not consent. Linking to it in the footer does not give you permission to set marketing cookies.

Ask AI for it

Draft a privacy policy for the product described below, written in plain English at roughly an eighth-grade reading level, not legalese. Structure it as a table of data categories where each row lists: what is collected, the purpose, the GDPR lawful basis, the retention period, and the third parties it reaches. Then add sections for recipients or categories of recipients (naming actual subprocessors where you know them), international transfers and the transfer mechanism, cookies and tracking with a link to the cookie policy, data subject rights with a working contact address, a response deadline and the right to complain to a supervisory authority, where data came from when it did not come from the user, any automated decision-making, children's data, security measures, how changes are announced, and a last-updated date. Mark every fact you had to guess with a bracketed TODO instead of inventing it, and add a short 'the short version' summary box at the top.

You might have meant

cookie policypersonal data piidata subject rightsgdprsubprocessor

Go deeper