IZN Tools

Privacy Policy Generator

A starting draft to hand a lawyer — not legal advice.

This is a template, not legal advice.

It produces a draft to review and to hand a lawyer. A policy that misdescribes how you handle data is worse than none — in most jurisdictions it is itself a violation. Read every section and correct anything that does not match what your site actually does.

What the site does
Jurisdictions

Privacy Policy for this site

Effective date: 2026-08-31

Before you publish this

This document was assembled from a template. It is not legal advice and it has not been reviewed by a lawyer.

Read every section and correct anything that does not describe what your site actually does. A policy that misdescribes your data handling is worse than no policy — in most jurisdictions it is itself a violation.

Have a qualified lawyer review it before you publish, especially if you serve users in the EU, the UK, or California.

Who we are

our site operates our site. This policy explains what personal data we collect, why we collect it, and what you can do about it. We are based in not specified.

What we collect

Usage data. We use web analytics to understand which pages are visited and how the site performs. This includes your IP address (usually truncated), browser and device type, referring page, and the pages you view.

Server logs. Our hosting provider records standard request logs — IP address, timestamp, requested URL and user agent — for security and diagnostics.

Cookies

We use cookies and similar browser storage. Strictly necessary cookies keep you signed in and remember your preferences; these cannot be switched off. Analytics and advertising cookies are only set after you agree to them, and you can change your choice at any time from the consent banner.

Who we share data with

We do not sell, rent or share your personal data with third parties.

How long we keep it

We keep personal data only as long as we need it. Account data is kept until you delete your account. Analytics and log data is kept for about 14 months and then deleted or anonymised.

Your rights

You can ask us what data we hold about you, ask us to correct it, or ask us to delete it. Write to the address below and we will respond within a reasonable time.

If you are in the EU, the EEA or the UK, the GDPR gives you the right to access your data, to have it corrected or erased, to restrict or object to how we use it, and to receive a copy in a portable format. Where we rely on your consent you can withdraw it at any time. You also have the right to complain to your national data protection authority.

Children

This site is not intended for children under 13 (or under 16 where local law sets that age), and we do not knowingly collect their personal data. If you believe a child has given us personal data, contact us and we will delete it.

Security

We take reasonable technical and organisational measures to protect personal data, including encryption in transit. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Changes to this policy

We may update this policy. When we do, we will change the effective date at the top, and for significant changes we will give notice on the site.

Contact

Questions about this policy or about your data: add an address.

11 sectionsHave a qualified lawyer review it before publishing, especially with users in the EU, UK or California.
Computed on this device

What this produces, and what it does not

It produces a structured draft that covers the sections a privacy policy normally needs, worded around the answers you give. It does not produce a document you can publish unread.

The distinction matters more here than with any other tool on this site. A wrong box-shadow looks bad. A wrong privacy policy is a false statement about how you handle other people's personal data.

Read these sections especially carefully

  • What you collect. The most common error is a template listing data you do not collect, or omitting something you do. Analytics, error tracking, session replay, chat widgets and embedded videos all collect data on your behalf.
  • Who you share with. Every third-party script is a processor. Your host, your mail sender, your CDN and your analytics provider all belong in the list.
  • Retention. Say a period you can actually honour. "Until you delete your account" is only true if deletion actually deletes.
  • Contact. Must be an address a person reads and answers.

Questions the draft will make you answer

Working through the options is useful even if you throw the output away, because each toggle is a question about your own system that has a factual answer:

  • Do you set any cookie before the visitor consents?
  • Which third parties receive data, and under what contract?
  • How long do your server logs actually live?
  • Can a user get their data deleted, and is there a process for it?

If you cannot answer one of these, that gap is the real finding — not the document.

Generated in your browser

Nothing you type is transmitted or stored. The whole document is assembled on this page, in English or Russian independently of the interface language.

Questions

Is this legal advice?+

No. It is a template, it has not been reviewed by a lawyer, and it cannot know your circumstances. Use it to produce a draft and to see which questions you need answers to, then have a qualified lawyer review it before you publish — particularly if you have users in the EU, the UK or California.

Can I just publish what it generates?+

You should not. Every section has to be checked against what your site actually does. A policy that misdescribes your data handling is worse than no policy at all: in most jurisdictions the inaccuracy is itself the violation, and it is the kind of thing that turns a complaint into a fine.

Do I need a privacy policy if I collect nothing?+

Usually yes, and it is short: it says you collect nothing. Most app stores, ad networks, analytics providers and payment processors require a policy as a condition of use, regardless of how little you collect. Saying "we collect nothing" clearly is also a real advantage worth publishing.

Does GDPR apply to me if I am not in the EU?+

It can. The GDPR applies based on where your users are, not where you are — if you offer a service to people in the EU or monitor their behaviour, it reaches you. The same logic applies to the CCPA and California residents. This is exactly the kind of question to put to a lawyer rather than to a generator.