DevTools Logo

Privacy Policy Generator

Privacy Policy Generator

Generate a starter privacy policy for your website — assembled entirely in your browser

Details

Fill in your site info and toggle sections

This is a starter template, not legal advice. Review with a professional before publishing.

Examples

Generate a cookies and GDPR starter

Input
Company: Acme Labs
Website: https://acme.example
Email: privacy@acme.example
Effective date: 2026-01-15
Cookies: on
Analytics: off
Third-party services: off
GDPR: on
CCPA: off
Output
# Privacy Policy

_Effective date: 2026-01-15_

Acme Labs ("we", "us", or "our") operates https://acme.example (the "Service"). This page informs you of our policies regarding the collection, use, and disclosure of personal data when you use our Service.

## Information We Collect
We collect information you provide directly to us, such as when you contact us, as well as information collected automatically as you use the Service.

## Cookies
We use cookies and similar tracking technologies to track activity on our Service and hold certain information. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent.

## Your Rights Under the GDPR
If you are in the European Economic Area (EEA), you have the right to access, correct, update, or request deletion of your personal data. You also have the right to object to processing, to data portability, and to withdraw consent at any time.

## Data Retention
We retain your personal data only for as long as is necessary for the purposes set out in this Privacy Policy.

## Contact Us
If you have any questions about this Privacy Policy, please contact us at privacy@acme.example.

Only the two enabled optional clauses are inserted between the always-present collection and retention sections.

Generate an analytics, vendor, and CCPA starter

Input
Company: Widget Co
Website: https://widgets.example
Email: legal@widgets.example
Effective date: 2026-02-01
Cookies: off
Analytics: on
Third-party services: on
GDPR: off
CCPA: on
Output
# Privacy Policy

_Effective date: 2026-02-01_

Widget Co ("we", "us", or "our") operates https://widgets.example (the "Service"). This page informs you of our policies regarding the collection, use, and disclosure of personal data when you use our Service.

## Information We Collect
We collect information you provide directly to us, such as when you contact us, as well as information collected automatically as you use the Service.

## Analytics
We may use third-party analytics services to monitor and analyze the use of our Service. These services collect usage data such as pages visited, time on site, and referring URLs.

## Third-Party Services
We may employ third-party companies and individuals to facilitate our Service, provide the Service on our behalf, or assist us in analyzing how our Service is used. These third parties have access to your personal data only to perform these tasks on our behalf.

## Your Rights Under the CCPA
If you are a California resident, you have the right to know what personal information we collect, to request deletion of your personal information, and to opt out of the sale of your personal information. We do not sell your personal information.

## Data Retention
We retain your personal data only for as long as is necessary for the purposes set out in this Privacy Policy.

## Contact Us
If you have any questions about this Privacy Policy, please contact us at legal@widgets.example.

Analytics, third-party, and CCPA switches insert their fixed generic sections while Cookies and GDPR remain absent.

About this tool

Privacy Policy Generator assembles a Markdown starter policy from a company name, website URL, contact email, effective date, and five optional section switches. Information We Collect, Data Retention, and Contact Us are always included; Cookies, Analytics, Third-Party Services, GDPR rights, and CCPA rights appear only when enabled.

The output updates in the browser as the form changes and can be copied as Markdown. Blank company, website, email, and date values fall back to Your Company, https://example.com, privacy@example.com, and YYYY-MM-DD, so the preview remains complete while a draft is being configured.

The generated clauses are generic rather than a record of actual processing. They do not inventory data categories, vendors, legal bases, retention schedules, security practices, transfers, children's data, or jurisdiction-specific obligations. The component explicitly presents the result as a starter template, not legal advice, and it should be reviewed and customized before publication.

How to use

  1. Enter accountable-party details

    Replace the company, website, contact email, and effective date with accurate publishable values instead of leaving the fallback placeholders.

  2. Select only applicable sections

    Enable Cookies, Analytics, Third-Party Services, GDPR, and CCPA only when each generic clause reflects the site's real behavior and legal scope.

  3. Customize the Markdown

    Copy the generated draft and add the actual data categories, purposes, vendors, retention periods, request process, and any other disclosures your service requires.

  4. Review before publishing

    Have an appropriately qualified reviewer confirm the statements, links, jurisdictional coverage, and effective date before placing the policy on the site.

Use cases

Scaffolding a new website policy

Create a structured Markdown starting point before replacing generic language with the service's actual data practices.

Comparing optional disclosures

Preview how cookies, analytics, service-provider, GDPR, and CCPA sections change the outline of a draft.

Preparing a legal-review brief

Supply counsel or a privacy reviewer with an organized baseline plus the product's concrete processing details and open questions.

Creating a non-production placeholder

Use a clearly marked draft in a prototype while the final, fact-checked policy is being prepared.

Common mistakes

Mistake:Publishing the generated Markdown unchanged and treating it as legal advice.

Fix:Use it as a starter only. Reconcile every sentence with actual processing and obtain qualified review appropriate to the service and jurisdictions.

Mistake:Enabling a jurisdiction switch solely because the business is located there.

Fix:Determine scope from the users, data, activities, thresholds, and applicable law, then tailor rights and request procedures rather than relying on a generic toggle.

Mistake:Enabling CCPA without verifying the fixed statement that the company does not sell personal information.

Fix:Confirm the statement is true under the applicable definitions and replace the generic clause with accurate sale, sharing, opt-out, and request disclosures.

Mistake:Leaving placeholders or generic vendor and retention language in the published policy.

Fix:Replace fallback contact details and YYYY-MM-DD, identify relevant services and purposes, and document concrete retention criteria before release.

Frequently asked questions

References & standards