What this produces, and what it does not
It produces a structured draft that covers the sections a privacy policy normally needs, worded around the answers you give. It does not produce a document you can publish unread.
The distinction matters more here than with any other tool on this site. A wrong
box-shadow looks bad. A wrong privacy policy is a false statement about how you
handle other people's personal data.
Read these sections especially carefully
- What you collect. The most common error is a template listing data you do not collect, or omitting something you do. Analytics, error tracking, session replay, chat widgets and embedded videos all collect data on your behalf.
- Who you share with. Every third-party script is a processor. Your host, your mail sender, your CDN and your analytics provider all belong in the list.
- Retention. Say a period you can actually honour. "Until you delete your account" is only true if deletion actually deletes.
- Contact. Must be an address a person reads and answers.
Questions the draft will make you answer
Working through the options is useful even if you throw the output away, because each toggle is a question about your own system that has a factual answer:
- Do you set any cookie before the visitor consents?
- Which third parties receive data, and under what contract?
- How long do your server logs actually live?
- Can a user get their data deleted, and is there a process for it?
If you cannot answer one of these, that gap is the real finding — not the document.
Generated in your browser
Nothing you type is transmitted or stored. The whole document is assembled on this page, in English or Russian independently of the interface language.
Questions
Is this legal advice?+
No. It is a template, it has not been reviewed by a lawyer, and it cannot know your circumstances. Use it to produce a draft and to see which questions you need answers to, then have a qualified lawyer review it before you publish — particularly if you have users in the EU, the UK or California.
Can I just publish what it generates?+
You should not. Every section has to be checked against what your site actually does. A policy that misdescribes your data handling is worse than no policy at all: in most jurisdictions the inaccuracy is itself the violation, and it is the kind of thing that turns a complaint into a fine.
Do I need a privacy policy if I collect nothing?+
Usually yes, and it is short: it says you collect nothing. Most app stores, ad networks, analytics providers and payment processors require a policy as a condition of use, regardless of how little you collect. Saying "we collect nothing" clearly is also a real advantage worth publishing.
Does GDPR apply to me if I am not in the EU?+
It can. The GDPR applies based on where your users are, not where you are — if you offer a service to people in the EU or monitor their behaviour, it reaches you. The same logic applies to the CCPA and California residents. This is exactly the kind of question to put to a lawyer rather than to a generator.