Legal

Privacy Policy Generator

Answer a short form about what you collect, why, and who you share it with, and the policy assembles itself as you go, 12 to 14 sections covering collection, legal bases, cookies, processors, retention, security, and user rights. The document is built from your answers in code, not written by an AI, so the same answers always produce the same policy and nothing gets invented. It is a drafting tool, not legal advice.

  • Free to use
  • No sign-up
  • Instant results

This is a drafting tool, not legal advice. It assembles a policy from the facts you tick, so it is only as accurate as your answers. Have it reviewed by a qualified lawyer, and make sure it describes what you actually do with data before you publish it.

How it works

  1. 01 Fill in your organisation's details and tick what you actually collect.
  2. 02 Tick the purposes and the third-party services you use, each one is named in the policy.
  3. 03 Choose which laws apply so the right rights sections are included.
  4. 04 Download the PDF or copy the text, then have a lawyer review it before publishing.

Privacy policy do's and don'ts

A policy is a description of what you actually do. Most of the trouble comes from the gap between the document and the practice.

Do

  • Describe what you really collect today, not what you intend to collect one day.
  • Name your processors specifically: "we use analytics providers" is not a disclosure.
  • State a real retention period, or the concrete trigger that starts deletion.
  • Give one working contact address that a person actually monitors.
  • Date the policy, and keep an archive of previous versions.
  • Re-read it whenever you add a new tool that touches user data.
  • Have a lawyer in your jurisdiction review it before you publish.

Don't

  • Don't copy a competitor's policy, it describes their data flows, not yours.
  • Don't claim compliance with a law you have not actually implemented.
  • Don't promise "bank-level" or "military-grade" security; describe what you do instead.
  • Don't bury an opt-out you are legally required to make easy to find.
  • Don't say you never share data if analytics or hosting providers can access it.
  • Don't leave the policy unchanged after you add a payment processor or an AI feature.
  • Don't treat a generated draft as a substitute for legal review, including this one.

Frequently asked questions

Not by itself. A policy is compliant when it accurately describes what you do and meets the requirements of your jurisdiction. This gives you a complete, correctly structured draft covering the sections regulators expect, a qualified lawyer should review it before you publish.

No. The document is assembled in code from the boxes you tick, which is why the same answers always produce the same policy and why every data type and processor you declare actually appears in the text. AI is offered only as an optional plain-English rewrite of the finished draft, and it is instructed never to change a disclosure.

Yes, pick which applies and the matching sections are included: legal bases for processing and the full data-subject rights list for GDPR, and the know/delete/correct/opt-out rights plus a sale-and-sharing statement for CCPA/CPRA. Choose Both and you get both.

No. The whole policy is generated in your browser and saved only in your own local storage. Text is sent to the AI provider only if you press the plain-English rewrite button.

Come back, change the answers, and regenerate, your draft is saved in the browser. An out-of-date policy that misdescribes what you actually do is a bigger risk than an imperfect one.

Related tools