Skip to content


Question 1 of 10

01The basics

What is the business called?

The legal or trading name. It appears throughout the document.

Enter to continue

What this generator asks, and what it writes

Ten questions produce a document of 12 sections. Answers change the wording, not just the blanks, so two sites with different obligations get different policies.

The questions

  1. What is the business called?

    The legal or trading name. It appears throughout the document.

  2. What is the website address?

    One domain per policy. Include the protocol.

  3. How should people contact you about their data?

    Privacy law expects a route that a person can actually use.

    Choices: Email address, Contact form on the site, Mailing address, Email and mailing address.

  4. What is the address?

    This is printed in the contact section exactly as written.

  5. What do you collect from visitors?

    Pick everything that applies. Each one adds a line to the collection section.

    Choices: Names and email addresses, Payment details, Messages sent through forms, Account credentials, IP addresses and device data, None of these.

  6. What measures traffic on the site?

    Third party analytics has to be disclosed by name.

    Choices: Google Analytics, Server logs, A privacy-first analytics tool, Nothing at all.

  7. Which cookies does the site set?

    Advertising cookies change what the sharing section has to say.

    Choices: Essential only, Essential and analytics, Essential, analytics, and advertising.

  8. Do you sell or share personal information?

    California defines sharing broadly. Ad partners usually count.

    Choices: No, never, Only with service providers acting on our behalf, Yes, with advertising partners.

  9. Where are your visitors?

    California adds CCPA rights. The EU or UK adds GDPR.

    Choices: United States, California, European Union or UK, Canada.

  10. When does this take effect?

    Usually the day you publish it.

The sections it writes

  1. Introduction

    Names the operator, the site the policy covers, and the sites it does not.

  2. Who we are

    Identifies the party accountable for the information described.

  3. How to reach us

    Gives a working route for access, correction, and deletion requests.

  4. Information you provide

    Lists what a visitor hands over directly, drawn from the collection answers.

  5. Information collected automatically

    Covers server-side logging and what the site does not build from it.

  6. Cookies and similar technologies

    States which cookie categories the site sets and what blocking them costs.

  7. Analytics and measurement

    Names the measurement tools in use, since third parties must be disclosed.

  8. How we use information

    Explains purpose limitation and rules out automated decision making.

  9. Sharing and disclosure

    Distinguishes service providers from sale or cross-context advertising.

  10. Retention and security

    Sets a retention principle and describes safeguards without overclaiming.

  11. Your privacy rights

    Grows or shrinks with the regions selected, adding CCPA, GDPR, or PIPEDA language.

  12. Effective date and changes

    Fixes the effective date and commits to posting revisions in the same place.