Skip to content
Business Tools

Free website document generators

The pages your site is expected to publish: a privacy policy, terms of service, and a cookie policy. Answer questions about how your site actually works and get language that matches. No account, no email, and nothing you type leaves your browser.


Three documents most sites are expected to publish, and most small sites either skip or copy from somebody else. These generators ask about how your site actually works, then write language that matches the answers. A site with EU visitors gets different wording than one without. Everything runs in your browser, and nothing you type is sent anywhere.

The generators

Which ones does your site need

Not every site needs all three. What decides it is what your site does, not what kind of business you are.

If

Your site collects anything at all

Privacy policy

A contact form, an email signup, analytics, or server logs. That is almost every site on the internet, including the ones that believe they collect nothing. If a visitor can type into it or a script is measuring them, you are collecting.

If

Visitors can do something, not just read

Terms of service

Accounts, purchases, bookings, downloads, comments, or uploads. Terms set out what you are offering, what visitors may do with it, and who carries the risk when something breaks. A brochure site with no interaction can reasonably skip them.

If

You set cookies beyond the strictly necessary

Cookie policy

Analytics, advertising pixels, embedded video, or anything remembering a visitor between sessions. If you show a consent banner, you need somewhere for it to link to, and that somewhere is this document.

Why a copied policy is worse than none

Copying a privacy policy from a site you admire is the most common shortcut on the small web, and it is the one that creates real exposure. That document describes somebody else's data practices. It will claim things you do not do, and it will leave out things you do.

Both directions are a problem. A policy promising you never use analytics, on a site running analytics, is a public statement you are not honouring. A policy silent about your email platform gives a visitor no way to understand where their address ends up. Regulators and visitors both read the document as a description of reality, because that is what it claims to be.

The questions these generators ask exist for that reason. What comes out reflects the answers you gave, so the document describes your site rather than one that resembles it.

What these do not do

Worth being direct about, because a generator that oversells itself is more dangerous than no generator.

  • These are not legal advice, and no generator is.
  • Health data, financial data, and anything involving children carry obligations well beyond what a questionnaire can cover.
  • Operating across several jurisdictions is exactly where paying a lawyer pays for itself.
  • A published document has to stay true. When what your site does changes, the document changes with it.

For most small sites and nonprofits, an accurate generated document beats an inherited one by a wide margin, and beats an empty footer link by more. That is the bar these are built to clear.

Common questions

Are these generators free?

Yes. No account, no email, no paid tier, and no limit on how many documents you produce.

Can I just copy a policy from another site?

You can, and it is the most common mistake on small sites. A copied policy describes another company's data practices, which means it is either claiming things you do not do or missing things you do. A document that misdescribes your own site is worse than no document, because it is a public statement you are not living up to.

Do my answers get uploaded anywhere?

No. The generators run in your browser. Your answers are assembled into a document on your own device and never sent to a server.

Which documents does a small site actually need?

Nearly every site needs a privacy policy, because nearly every site collects something, even if only server logs and analytics. Terms of service matter once visitors can do something rather than just read. A cookie policy is needed once you set cookies beyond the strictly necessary, which any analytics or advertising script does.

Is this enough for GDPR or CCPA?

The generators are written against those frameworks and ask the questions that decide which language applies, so what you get reflects how your site actually works rather than a template. That is a real starting point, not a compliance certificate. Compliance is about what your site does, and the document only describes it.

How often should I update these?

Whenever what your site does changes. Adding analytics, a payment processor, a new embed, or an email platform all change what the document should say. Re-running the generator takes a few minutes and is worth doing at least annually.

Other tools on this site

The document is the easy part

Writing an accurate privacy policy takes ten minutes once you know what your site collects. Finding that out is the hard part, and most organisations cannot answer it, because the answer is spread across a tag manager nobody audits, three plugins nobody chose, and an email platform somebody set up in 2019.

That is the work I do. Westphal Solutions builds websites, tools, and reporting for nonprofits and growing teams, including the audit that tells you what your site is actually doing before you publish a document claiming to describe it.

Start a conversation