Privacy Policy Generator
Overview
Scans a website or application codebase to detect data collection signals — cookies,
web forms, payment processors, analytics scripts, social media embeds, and third-party
trackers — then generates a tailored privacy policy with 12 sections. Includes specific
GDPR rights (7 individual rights), CCPA rights (6 consumer rights), and cookie consent
banner text in both minimal and full GDPR formats.
The detection phase maps every data touchpoint to its legal basis and disclosure
requirement, ensuring the generated policy accurately reflects actual data practices
rather than relying on generic boilerplate.
Legal Disclaimer: This skill generates template documents for informational and
educational purposes only. Generated privacy policies are not a substitute for legal
advice. Data protection requirements vary by jurisdiction, industry, and data type.
All documents should be reviewed by a licensed attorney and/or data protection officer
before publication. No attorney-client relationship is created by using this tool.
Prerequisites
- A live website URL or local codebase to scan
- Knowledge of the business entity name and jurisdiction
- Understanding of what data is collected and why (the scan detects signals but cannot
capture server-side-only processing)
Instructions
Scan for data collection signals. Use WebFetch on the target URL to detect:
| Signal Category |
What to Look For |
| Cookies |
Set-Cookie headers, cookie consent banners, tracking pixels |
| Analytics |
Google Analytics, Mixpanel, Amplitude, Hotjar, Segment |
| Forms |
Contact forms, registration, login, newsletter signup |
| Payments |
Stripe, PayPal, Square, Braintree, payment form fields |
| Social |
Facebook Pixel, Twitter tags, LinkedIn Insight, social login |
| Advertising |
Google Ads, Facebook Ads, retargeting pixels |
| CDN/Third-Party |
Cloudflare, AWS CloudFront, Google Fonts, embedded iframes |
| Chat/Support |
Intercom, Zendesk, Drift, live chat widgets |
If scanning a codebase instead, use Glob and Grep to find:
- Cookie-setting code (
document.cookie, setCookie, cookies middleware)
- Analytics initialization (
gtag, analytics.track, mixpanel.init)
- Form handlers and data submission endpoints
- Payment SDK imports and configurations
- User model/schema definitions showing stored fields
- Environment variables referencing third-party API keys
Classify data types collected. Map detected signals to data categories:
- Identifiers (name, email, phone, address)
- Financial (payment card, bank account, transaction history)
- Technical (IP address, device info, browser fingerprint)
- Behavioral (browsing history, click patterns, purchase history)
- Content (user uploads, messages, reviews)
- Sensitive (health, biometric, political — flag these for special handling)
Determine legal bases (GDPR). For each data category, assign:
- Consent — marketing emails, non-essential cookies, analytics
- Contract — account data, payment processing, service delivery
- Legitimate interest — security logs, fraud prevention, basic analytics
- Legal obligation — tax records, regulatory reporting
Generate the 12-section privacy policy:
| # |
Section |
Covers |
| 1 |
Introduction |
Who the company is, what this policy covers |
| 2 |
Information We Collect |
Data types, collection methods, sources |
| 3 |
How We Use Your Information |
Purposes mapped to legal bases |
| 4 |
Cookies & Tracking |
Cookie types, duration, opt-out mechanisms |
| 5 |
Information Sharing |
Third parties, categories, purposes |
| 6 |
Data Retention |
How long each data type is kept |
| 7 |
Your Rights Under GDPR |
7 specific rights with exercise instructions |
| 8 |
Your Rights Under CCPA |
6 specific rights with exercise instructions |
| 9 |
Data Security |
Technical and organizational measures |
| 10 |
International Transfers |
Cross-border data flow safeguards |
| 11 |
Children's Privacy |
Age restrictions, COPPA compliance |
| 12 |
Contact & Updates |
DPO contact, policy change notification |
Detail GDPR rights (Section 7). Include all seven with exercise instructions:
- Right of Access (Article 15) — request a copy of personal data
- Right to Rectification (Article 16) — correct inaccurate data
- Right to Erasure (Article 17) — "right to be forgotten"
- Right to Restrict Processing (Article 18) — limit data use
- Right to Data Portability (Article 20) — receive data in machine-readable format
- Right to Object (Article 21) — object to processing based on legitimate interest
- Rights Related to Automated Decision-Making (Article 22) — opt out of profiling
Detail CCPA rights (Section 8). Include all six:
- Right to Know — what personal information is collected
- Right to Delete — request deletion of personal information
- Right to Opt-Out — "Do Not Sell or Share My Personal Information"
- Right to Non-Discrimination — equal service regardless of rights exercised
- Right to Correct — correct inaccurate personal information
- Right to Limit Use of Sensitive Information — restrict sensitive data processing
Generate cookie consent banner text. Two versions:
- Minimal (US): Brief notice with link to full policy
- Full GDPR: Granular consent with necessary/analytics/marketing toggles
Tag assumptions. Insert [VERIFY] for any data practice inferred from signals
but not confirmed by the user (e.g., [VERIFY: Google Analytics detected — confirm if IP anonymization is enabled]).
Write the output file using the naming convention below.
Output
Generate a single Markdown file named PRIVACY-POLICY-{company}-{YYYY-MM-DD}.md with:
# Privacy Policy
**{Company Name}**
**Last Updated:** {date}
**Effective Date:** {date}
---
## Data Collection Summary
| Data Type | Source | Legal Basis | Retention |
|-----------|--------|-------------|-----------|
{table of all detected data points}
---
## 1. Introduction
{formal legal text}
> **Plain English:** {simple explanation}
{... sections 2-12 ...}
---
## Cookie Consent Banner Text
### Minimal Version (US)
{banner text}
### Full GDPR Version
{banner text with granular consent options}
---
**[VERIFY] Tags Summary:**
{numbered list of assumptions}
**Detection Results:** {count} data signals detected across {count} categories
**Generated by:** Legal Assistant Plugin — Not a substitute for legal counsel.
Error Handling
| Error |
Cause |
Solution |
| Website unreachable |
URL down or behind authentication |
Ask for a description of data practices or codebase path |
| No data signals detected |
Static site with no tracking |
Generate minimal policy covering server logs and hosting |
| Sensitive data detected |
Health, biometric, or financial data |
Flag for enhanced protection; recommend DPO consultation |
| Multiple jurisdictions |
Global audience detected |
Include both GDPR and CCPA sections, add [VERIFY] for others |
| Server-side processing invisible |
Cannot detect backend data flows |
Ask user to describe server-side data collection |
| Third-party script unrecognized |
Unknown tracking pixel or SDK |
List as "unidentified third-party service" with [VERIFY] |
Examples
Example 1: SaaS with Analytics and Payments
Request: "Generate a privacy policy for https://example-app.com"
Result: PRIVACY-POLICY-ExampleApp-2026-04-02.md detecting:
- Google Analytics 4 (behavioral data, IP address)
- Stripe payment processing (financial data)
- Intercom chat widget (identifiers, conversation content)
- HubSpot forms (email, name, company)
- 12-section policy with GDPR + CCPA rights
- Cookie consent banner in both formats
- 6 [VERIFY] tags for server-side assumptions
Example 2: Content Blog with Newsletter
Request: "Create privacy policy for my WordPress blog with Mailchimp newsletter"
Result: PRIVACY-POLICY-MyBlog-2026-04-02.md detecting:
- WordPress cookies (session, comment author)
- Mailchimp email collection (consent-based)
- Google Fonts (IP address to Google servers)
- Simplified policy focusing on minimal data collection
- GDPR consent basis for newsletter subscription
Resources
1---2name: privacy-generator3description: Generates comprehensive privacy policies by scanning websites for data collection signals including cookies, forms, payment processors, and third-party scripts. Use when launching a website or app that collects user data and needs GDPR/CCPA compliance. Trigger with "/privacy-generator" or "create a privacy policy for my website".4license: MIT5---6# Privacy Policy Generator
7
8## Overview
9
10Scans a website or application codebase to detect data collection signals — cookies,
11web forms, payment processors, analytics scripts, social media embeds, and third-party
12trackers — then generates a tailored privacy policy with 12 sections. Includes specific
13GDPR rights (7 individual rights), CCPA rights (6 consumer rights), and cookie consent
14banner text in both minimal and full GDPR formats.
15
16The detection phase maps every data touchpoint to its legal basis and disclosure
17requirement, ensuring the generated policy accurately reflects actual data practices
18rather than relying on generic boilerplate.
19
20> **Legal Disclaimer:** This skill generates template documents for informational and
21> educational purposes only. Generated privacy policies are not a substitute for legal
22> advice. Data protection requirements vary by jurisdiction, industry, and data type.
23> All documents should be reviewed by a licensed attorney and/or data protection officer
24> before publication. No attorney-client relationship is created by using this tool.
25
26## Prerequisites
27
28- A live website URL or local codebase to scan
29- Knowledge of the business entity name and jurisdiction
30- Understanding of what data is collected and why (the scan detects signals but cannot
31 capture server-side-only processing)
32
33## Instructions
34
351. **Scan for data collection signals.** Use WebFetch on the target URL to detect:
36
37 | Signal Category | What to Look For |
38 |----------------|------------------|
39 | Cookies | `Set-Cookie` headers, cookie consent banners, tracking pixels |
40 | Analytics | Google Analytics, Mixpanel, Amplitude, Hotjar, Segment |
41 | Forms | Contact forms, registration, login, newsletter signup |
42 | Payments | Stripe, PayPal, Square, Braintree, payment form fields |
43 | Social | Facebook Pixel, Twitter tags, LinkedIn Insight, social login |
44 | Advertising | Google Ads, Facebook Ads, retargeting pixels |
45 | CDN/Third-Party | Cloudflare, AWS CloudFront, Google Fonts, embedded iframes |
46 | Chat/Support | Intercom, Zendesk, Drift, live chat widgets |
47
482. **If scanning a codebase instead**, use Glob and Grep to find:
49 - Cookie-setting code (`document.cookie`, `setCookie`, `cookies` middleware)
50 - Analytics initialization (`gtag`, `analytics.track`, `mixpanel.init`)
51 - Form handlers and data submission endpoints
52 - Payment SDK imports and configurations
53 - User model/schema definitions showing stored fields
54 - Environment variables referencing third-party API keys
55
563. **Classify data types collected.** Map detected signals to data categories:
57 - Identifiers (name, email, phone, address)
58 - Financial (payment card, bank account, transaction history)
59 - Technical (IP address, device info, browser fingerprint)
60 - Behavioral (browsing history, click patterns, purchase history)
61 - Content (user uploads, messages, reviews)
62 - Sensitive (health, biometric, political — flag these for special handling)
63
644. **Determine legal bases (GDPR).** For each data category, assign:
65 - **Consent** — marketing emails, non-essential cookies, analytics
66 - **Contract** — account data, payment processing, service delivery
67 - **Legitimate interest** — security logs, fraud prevention, basic analytics
68 - **Legal obligation** — tax records, regulatory reporting
69
705. **Generate the 12-section privacy policy:**
71
72 | # | Section | Covers |
73 |---|---------|--------|
74 | 1 | Introduction | Who the company is, what this policy covers |
75 | 2 | Information We Collect | Data types, collection methods, sources |
76 | 3 | How We Use Your Information | Purposes mapped to legal bases |
77 | 4 | Cookies & Tracking | Cookie types, duration, opt-out mechanisms |
78 | 5 | Information Sharing | Third parties, categories, purposes |
79 | 6 | Data Retention | How long each data type is kept |
80 | 7 | Your Rights Under GDPR | 7 specific rights with exercise instructions |
81 | 8 | Your Rights Under CCPA | 6 specific rights with exercise instructions |
82 | 9 | Data Security | Technical and organizational measures |
83 | 10 | International Transfers | Cross-border data flow safeguards |
84 | 11 | Children's Privacy | Age restrictions, COPPA compliance |
85 | 12 | Contact & Updates | DPO contact, policy change notification |
86
876. **Detail GDPR rights (Section 7).** Include all seven with exercise instructions:
88 1. Right of Access (Article 15) — request a copy of personal data
89 2. Right to Rectification (Article 16) — correct inaccurate data
90 3. Right to Erasure (Article 17) — "right to be forgotten"
91 4. Right to Restrict Processing (Article 18) — limit data use
92 5. Right to Data Portability (Article 20) — receive data in machine-readable format
93 6. Right to Object (Article 21) — object to processing based on legitimate interest
94 7. Rights Related to Automated Decision-Making (Article 22) — opt out of profiling
95
967. **Detail CCPA rights (Section 8).** Include all six:
97 1. Right to Know — what personal information is collected
98 2. Right to Delete — request deletion of personal information
99 3. Right to Opt-Out — "Do Not Sell or Share My Personal Information"
100 4. Right to Non-Discrimination — equal service regardless of rights exercised
101 5. Right to Correct — correct inaccurate personal information
102 6. Right to Limit Use of Sensitive Information — restrict sensitive data processing
103
1048. **Generate cookie consent banner text.** Two versions:
105 - **Minimal (US):** Brief notice with link to full policy
106 - **Full GDPR:** Granular consent with necessary/analytics/marketing toggles
107
1089. **Tag assumptions.** Insert `[VERIFY]` for any data practice inferred from signals
109 but not confirmed by the user (e.g., `[VERIFY: Google Analytics detected — confirm
110 if IP anonymization is enabled]`).
111
11210. **Write the output file** using the naming convention below.
113
114## Output
115
116Generate a single Markdown file named `PRIVACY-POLICY-{company}-{YYYY-MM-DD}.md` with:
117
118```
119# Privacy Policy
120**{Company Name}**
121
122**Last Updated:** {date}
123**Effective Date:** {date}
124
125---
126
127## Data Collection Summary
128| Data Type | Source | Legal Basis | Retention |
129|-----------|--------|-------------|-----------|
130{table of all detected data points}
131
132---
133
134## 1. Introduction
135{formal legal text}
136
137> **Plain English:** {simple explanation}
138
139{... sections 2-12 ...}
140
141---
142
143## Cookie Consent Banner Text
144
145### Minimal Version (US)
146{banner text}
147
148### Full GDPR Version
149{banner text with granular consent options}
150
151---
152
153**[VERIFY] Tags Summary:**
154{numbered list of assumptions}
155
156**Detection Results:** {count} data signals detected across {count} categories
157**Generated by:** Legal Assistant Plugin — Not a substitute for legal counsel.
158```
159
160## Error Handling
161
162| Error | Cause | Solution |
163|-------|-------|----------|
164| Website unreachable | URL down or behind authentication | Ask for a description of data practices or codebase path |
165| No data signals detected | Static site with no tracking | Generate minimal policy covering server logs and hosting |
166| Sensitive data detected | Health, biometric, or financial data | Flag for enhanced protection; recommend DPO consultation |
167| Multiple jurisdictions | Global audience detected | Include both GDPR and CCPA sections, add [VERIFY] for others |
168| Server-side processing invisible | Cannot detect backend data flows | Ask user to describe server-side data collection |
169| Third-party script unrecognized | Unknown tracking pixel or SDK | List as "unidentified third-party service" with [VERIFY] |
170
171## Examples
172
173**Example 1: SaaS with Analytics and Payments**
174
175Request: "Generate a privacy policy for https://example-app.com"
176
177Result: `PRIVACY-POLICY-ExampleApp-2026-04-02.md` detecting:
178
179- Google Analytics 4 (behavioral data, IP address)
180- Stripe payment processing (financial data)
181- Intercom chat widget (identifiers, conversation content)
182- HubSpot forms (email, name, company)
183- 12-section policy with GDPR + CCPA rights
184- Cookie consent banner in both formats
185- 6 [VERIFY] tags for server-side assumptions
186
187**Example 2: Content Blog with Newsletter**
188
189Request: "Create privacy policy for my WordPress blog with Mailchimp newsletter"
190
191Result: `PRIVACY-POLICY-MyBlog-2026-04-02.md` detecting:
192
193- WordPress cookies (session, comment author)
194- Mailchimp email collection (consent-based)
195- Google Fonts (IP address to Google servers)
196- Simplified policy focusing on minimal data collection
197- GDPR consent basis for newsletter subscription
198
199## Resources
200
201- ICO Privacy Notice Code of Practice — UK data protection authority
202- [California Attorney General CCPA Guidance](https://oag.ca.gov/privacy/ccpa) — Official CCPA regulations
203- [FTC Data Security Guidance](https://www.ftc.gov/business-guidance/privacy-security) — Federal data protection standards
204- [GDPR Full Text (EUR-Lex)](https://eur-lex.europa.eu/eli/reg/2016/679/oj) — Official GDPR regulation
205- [NIST Privacy Framework](https://www.nist.gov/privacy-framework) — US government privacy standards
206- [CommonPaper DPA](https://commonpaper.com/standards/data-processing-agreement/) — CC BY 4.0 data processing terms