TOOLTIKI Lovable tool, really free
SEO & web Legal

Privacy policy generator

Generated in your browser · nothing is uploaded

Local · a starting point, not legal advice
Advertisement
320 × 100

Builds a privacy policy skeleton covering only the things you say your site actually does. It is a starting point that needs reading and editing — not a compliant document, and the output says so at the top.

How to use the privacy policy generator

1 Fill in your site details.
2 Answer honestly about analytics, cookies, forms and payments — a policy describing things you do not do is worse than none.
3 Read every line of the output and change anything that is not true.

A privacy policy is a description of what a specific site actually does with data. No generator knows that, which is why every section here appears only if you say it applies, and why the output opens by telling you to read it. A generated policy that quietly claims you set no cookies while you run analytics is worse than having no policy at all: it is a false statement about your data handling, in writing, on your own site.

What the law generally requires is narrower than most policies suggest, and it is roughly the same across the UK GDPR, the EU GDPR and the CCPA: say who you are, what you collect, why you are allowed to, who else sees it, how long you keep it, and how someone exercises their rights. The generated document covers those, and the sections not relevant to you are simply absent rather than padded with clauses that do not apply.

The lawful basis is the part that changes with your answers rather than being boilerplate. A site with accounts and payments is processing to fulfil a contract; a plain content site relies on legitimate interests and on consent for non-essential cookies. Those are genuinely different justifications and stating the wrong one is a real error.

One clarification about cookie consent, because generators muddle it constantly: essential cookies do not need consent. Anything else — analytics, advertising, embedded media that tracks — does, and it must be consent before the cookie is set rather than a banner that says "by continuing you agree". A policy alone does not satisfy that; a consent mechanism does.

This is not legal advice. For anything with real exposure — health data, children, large-scale profiling — the cost of an hour with a solicitor is small against the cost of getting it wrong.

Questions

No. It is a skeleton describing what you said your site does. It has to be read and edited, and it says so at the top.

ICO — what to include in a privacy noticeEU GDPR — Article 13
Advertisement
300 × 250
Was this tool any good?
INTERNAL SIGNAL ONLY · WE USE IT TO FIND TOOLS WORTH REBUILDING