SEO & web Legal

Privacy policy generator

Generated in your browser · nothing is uploaded

Local · a starting point, not legal advice

Builds a privacy policy skeleton covering only the things you say your site actually does. It is a starting point that needs reading and editing, not a compliant document, and the output says so at the top.

How to use the privacy policy generator

1 Fill in your site details.
2 Answer honestly about analytics, cookies, forms and payments — a policy describing things you do not do is worse than none.
3 Read every line of the output and change anything that is not true.

A privacy policy is a description of what a specific site actually does with data. No generator knows that, which is why every section here appears only if you say it applies, and why the output opens by telling you to read it. A generated policy that quietly claims you set no cookies while you run analytics is worse than having no policy at all: it is a false statement about your data handling, in writing, on your own site.

What the law generally requires is narrower than most policies suggest, and it is roughly the same across the UK GDPR, the EU GDPR and the CCPA: say who you are, what you collect, why you are allowed to, who else sees it, how long you keep it, and how someone exercises their rights. The generated document covers those, and the sections not relevant to you are simply absent rather than padded with clauses that do not apply.

The lawful basis is the part that changes with your answers rather than being boilerplate. A site with accounts and payments is processing to fulfil a contract; a plain content site relies on legitimate interests and on consent for non-essential cookies. Those are genuinely different justifications and stating the wrong one is a real error.

One clarification about cookie consent, because generators muddle it constantly: essential cookies do not need consent. Anything else — analytics, advertising, embedded media that tracks. Does, and it must be consent before the cookie is set rather than a banner that says "by continuing you agree". A policy alone does not satisfy that; a consent mechanism does.

This is not legal advice. For anything with real exposure: health data, children, large-scale profiling. The cost of an hour with a solicitor is small against the cost of getting it wrong.

What people use it for

  • A policy page for a site that has none, before an ad network or app store review
  • Replacing a copied policy that describes practices the site does not follow
  • Working out which disclosures a plain content site actually owes
  • Updating the page after adding analytics or a contact form
  • A first draft to take to a solicitor rather than paying for one written from nothing

Questions

No. It is a skeleton describing what you said your site does. It has to be read and edited, and it says so at the top.

ICO: what privacy information should we provide?EU GDPR, Article 13
Was this tool any good?
Internal signal only · I use it to find the tools worth rebuilding