Answer a short form about what you collect, why, and who you share it with, and the policy assembles itself as you go, 12 to 14 sections covering collection, legal bases, cookies, processors, retention, security, and user rights. The document is built from your answers in code, not written by an AI, so the same answers always produce the same policy and nothing gets invented. It is a drafting tool, not legal advice.
This is a drafting tool, not legal advice. It assembles a policy from the facts you tick, so it is only as accurate as your answers. Have it reviewed by a qualified lawyer, and make sure it describes what you actually do with data before you publish it.
A policy is a description of what you actually do. Most of the trouble comes from the gap between the document and the practice.
Not by itself. A policy is compliant when it accurately describes what you do and meets the requirements of your jurisdiction. This gives you a complete, correctly structured draft covering the sections regulators expect, a qualified lawyer should review it before you publish.
No. The document is assembled in code from the boxes you tick, which is why the same answers always produce the same policy and why every data type and processor you declare actually appears in the text. AI is offered only as an optional plain-English rewrite of the finished draft, and it is instructed never to change a disclosure.
Yes, pick which applies and the matching sections are included: legal bases for processing and the full data-subject rights list for GDPR, and the know/delete/correct/opt-out rights plus a sale-and-sharing statement for CCPA/CPRA. Choose Both and you get both.
No. The whole policy is generated in your browser and saved only in your own local storage. Text is sent to the AI provider only if you press the plain-English rewrite button.
Come back, change the answers, and regenerate, your draft is saved in the browser. An out-of-date policy that misdescribes what you actually do is a bigger risk than an imperfect one.