Privacy policy generator that checks what your site actually collects
Most privacy policy generators ask twenty questions and still miss the analytics tag or the newsletter form on your site. This prompt has your todo.is agent visit your website, note the forms, cookies and third-party tools it can see, and write a privacy policy that matches what you really do, ready to paste into a page.
The prompt
- Write a privacy policy for [WEBSITE OR APP NAME AND URL], run by [BUSINESS NAME, COUNTRY AND CONTACT EMAIL]. Visit the site and list the forms, cookies, analytics, payment and marketing tools you can detect. Data we collect on purpose: [DATA YOU COLLECT AND WHY]. Our users are mainly in [REGIONS, E.G. EU, UK, CALIFORNIA]. Cover: what data we collect and how, why we use it and the legal basis, cookies, third parties we share with, international transfers, how long we keep data, security, users' rights and how to exercise them, children, changes to the policy, and contact details. Use plain English with short headings. Deliver it as a Word file and as clean HTML I can paste into my site, and list anything you could not confirm so I can check it.
What to change
- [WEBSITE OR APP NAME AND URL]: e.g. "Fernleaf Ceramics, fernleafceramics.com". Your agent opens it in a browser.
- [BUSINESS NAME, COUNTRY AND CONTACT EMAIL]: e.g. "Fernleaf Ceramics Ltd, United Kingdom, privacy@fernleafceramics.com".
- [DATA YOU COLLECT AND WHY]: e.g. "names and addresses for orders, emails for the newsletter, payment through Stripe".
- [REGIONS, E.G. EU, UK, CALIFORNIA]: Where your visitors or customers live. This decides which rules to cover, like GDPR or CCPA.
Example result
- What the agent found on the site
- • Newsletter signup form (collects email)
- • Checkout handled by Stripe (card details go to Stripe, not the shop)
- • An analytics script and a cookie banner
- • Embedded Instagram feed on the homepage
- Privacy Policy (sample draft)
- Who we are. Fernleaf Ceramics Ltd, United Kingdom. Contact: privacy@fernleafceramics.com.
- What we collect.
- • Order details: name, delivery address, email, phone
- • Newsletter: your email address, only if you sign up
- • Website use: pages visited and device type, through analytics cookies if you accept them
- Why we use it and the legal basis.
- • To deliver your order (contract)
- • To send our newsletter (your consent, which you can withdraw at any time)
- • To understand how the site is used (consent for analytics cookies)
- • To keep tax and accounting records (legal obligation)
- Who we share it with. Our payment provider, our email newsletter service, our delivery couriers and our website host. We do not sell your personal data.
- International transfers. Some providers may process data outside the UK. We rely on recognized safeguards such as standard contractual clauses.
- How long we keep it. Order records for 6 years for tax purposes. Newsletter data until you unsubscribe.
- Your rights. You can ask to access, correct, delete or move your data, object to processing, and complain to the data protection authority.
- Cookies. Essential cookies keep your basket working. Analytics cookies are only set if you accept them in the banner.
- Children. Our shop is not aimed at children under 13.
- Changes. We will update the date at the top when this policy changes.
- Please confirm
- • The name of your newsletter provider
- • Whether the Instagram embed sets cookies before consent
- • Your retention period for customer emails
How to do it with todo.is
- Copy the prompt and add your site address, business details and the data you collect.
- Paste it into todo.is on the Today screen. Your agent visits the site with a real browser.
- You get the policy as a Word file and as HTML, plus a short list of points to confirm.
- Paste the HTML into your privacy page. Later, ask your agent to update it when you add a new tool.
Tips for a better result
- List every third-party tool: analytics, email marketing, chat widgets, payment, ads pixels. These are what policies most often miss.
- If you have visitors in the EU or UK, analytics and ad cookies usually need consent first. Make sure your cookie banner matches the policy.
- Add a date at the top and update it when something changes.
- Set a recurring to-do: "every 6 months, re-check my site for new tracking tools and tell me if the privacy policy needs updating".
- This is a draft, not legal advice. For apps handling health, financial or children's data, have a privacy lawyer review it.
privacy policy generator: FAQ
- Do I legally need a privacy policy? If your website or app collects personal data such as emails, names or analytics, privacy laws in many places, including GDPR in the EU and UK and state laws in the US, require one. App stores and payment providers usually require it too.
- What is the difference between GDPR and CCPA in a privacy policy? GDPR policies explain the legal basis for each use and EU and UK rights like erasure. California's law focuses on the right to know, delete and opt out of the sale or sharing of data. Your agent covers the regions you list.
- Can I copy another website's privacy policy? Not a good idea. It may be copyrighted, and it describes their data practices, not yours. A policy that does not match what you do can cause more trouble than having none.
- Can the agent check a mobile app too? It cannot install your app, but it can read your app store listing and your website. Tell it which SDKs the app uses, such as analytics or crash reporting, and it adds them.
JavaScript is required to use the todo.is app.