A free privacy policy generator that asks what your site actually does — what you collect, which third parties you send it to, how long you keep it — and produces a policy that reflects the answers. It covers the disclosures GDPR and CCPA require. It is a solid starting document, not legal advice, and the difference matters.
No signupRuns in your browserNothing uploaded
Privacy Policy GeneratorLive
This tool is built for a wider screen — scroll sideways inside the frame, or turn your device.
How to use it
Four steps to a result
Describe your site or app
Your organisation's name, contact address and what the service does. Under GDPR you also need a contact point for data protection enquiries.
List what data you collect
Account details, analytics, cookies, payment information, support messages, uploaded files. Be honest — a policy that understates your collection is worse than none, because it is a misrepresentation.
Name your third parties
Every processor that touches user data: analytics, payments, email, hosting, error tracking, support chat. GDPR requires that these be disclosed, and it is the section most policies get wrong.
Publish and keep it current
Export the policy, publish it at a stable URL, link it from your footer and signup form — and revisit it whenever you add a new tool that touches user data.
Questions
Frequently asked questions
It is a strong starting point that covers the standard disclosures, and it is far better than the copied policy from an unrelated site that many small sites still run. It is not legal advice. If you process health or financial data, target children, or operate at scale, have a lawyer review it before you rely on it.
Yes. Analytics sets cookies or identifiers and processes personal data under GDPR, which triggers the disclosure requirement on its own. In practice you also need one to satisfy the app stores, ad networks, and payment processors, all of which check.
Your identity and contact details, the categories of data you collect, the purpose and the legal basis for each, who you share it with, any transfers outside the EU, retention periods, and the data subject rights — access, rectification, erasure, portability, objection — plus how to exercise them and how to complain to a supervisory authority.
CCPA applies to California residents and centres on disclosure and the right to opt out of the sale or sharing of personal information, including a conspicuous "Do Not Sell or Share My Personal Information" link where applicable. GDPR requires a lawful basis before you process at all, which is a higher bar than disclosure after the fact.
Whenever what you do with data changes — a new analytics tool, a new payment processor, a new data type, a new region. Review it annually regardless. Date the policy visibly, and notify users of material changes rather than quietly editing the page.
Keep going
More free tools
Every one runs in your browser, with no account and nothing uploaded.