What a privacy policy has to cover
In plain words, a privacy policy answers six questions: who you are and how to contact you; what personal information you collect; why you collect it; who you share it with; how long you keep it; and what people can do about it. The GDPR’s Article 13 is a useful checklist even outside Europe: it asks for the purposes and legal basis of each use, the recipients, any transfers outside the EU, the retention period, people’s rights, the right to withdraw consent and the right to complain to a supervisory authority.
How to use this generator
- Tick only what you really collect. Open your sign-up form, analytics and payment setup and check.
- List your real service providers. Stripe, Google Analytics and Cloudflare are one-click examples, not assumptions; delete any you don’t use.
- Every [bracketed] placeholder is something the draft can’t know. The counter under the output tells you how many are left.
- Tick the EU/UK box to add the GDPR and UK GDPR rights: access, rectification, erasure, restriction, portability, objection, withdrawing consent and complaining to a regulator. They follow the GDPR’s rights chapter, Article 13 and Article 77, and the ICO’s guide to individual rights.
- Tick California to add the rights listed by the California Attorney General: to know, delete, correct, opt out of sale or sharing, limit the use of sensitive personal information, and not be discriminated against for using them.
A template is a starting point
Generic clauses can’t describe your product, so read every sentence and cut or change anything that isn’t true. A policy that promises more than you do is worse than a short, accurate one. For a real example in plain English, see our own privacy policy and terms. Then have a qualified lawyer review your draft, especially if you handle payments, health or children’s data, or sell to customers in several countries.
Next, draft your terms of service and cookie policy, and tick them off on the launch checklist.