WoluTools
← About this tool

legal · Browser tool

Privacy Policy Generator

Answer the questionnaire and a draft policy is composed from it as you type. Sections you have no answer for are left out rather than filled with boilerplate.

Runs in your browserNothing is uploadedHow it works
Free toolNo account · no job limitFree, unlimitedYour answers stay on this device. Nothing is sent anywhere.

This produces a draft, not a finished policy

The text below is assembled from what you type into the form. It cannot see your servers, your vendor contracts or the tracking script somebody added to the checkout page last year, so it can only describe what you tell it. A policy that misdescribes your data handling is a problem in itself, not a solution to one.

Read every line against what your systems actually do, then have a lawyer qualified in your jurisdiction review it before you publish. This page gives no legal advice. The same warning is written into the generated document, at the top, so it cannot be lost when you paste the text somewhere else — delete that section once the policy has been reviewed.

Who is publishing the policy

Which law applies

Regimes to cover

Changing the location above resets these two. Override them if your situation differs.

Data protection officer

A DPO is required when your core activity is large-scale monitoring of people or large-scale handling of special category data. Naming one who does not exist creates liability; leaving the box clear adds a sentence explaining why you have none.

What you collect, why, and for how long

Untick anything you do not do. The wording of each row goes into the policy as written, so edit it to match your system rather than leaving a description that is close but wrong.

Cookies and analytics

Categories in use

Processors and transfers

Rights, children, retention limits

Security measures you can honestly claim

Only tick what is true today. A claim you cannot evidence is worse than a shorter list.

The draft

View

What this does

The generator holds a set of written sections and decides which of them belong in your document. Answer that your users are in the EEA and the California section never appears; a policy listing CCPA rights for a company with no US users reads as copied from somewhere else, and a regulator will notice. Answer that you appointed no data protection officer and the policy says so with the reason, rather than staying quiet about it.

Lawful basis is the part people get wrong

The GDPR does not ask whether you have a good reason for processing data. It asks which of six named bases you rely on, per purpose, and the choice has consequences. Consent can be withdrawn and processing must then stop. Contract performance cannot be stretched to cover analytics, because the service works without them. Legitimate interest is available but requires you to have weighed your interest against the user's and to be able to show that balancing test if asked. Legal obligation covers the invoices you must keep for tax, which is why deletion requests do not reach them. Each row of the table has its own basis for this reason.

Where consent and policy get confused

A privacy policy describes the cookies you set. A consent banner decides whether they get set at all. They are separate pieces of work and they have to agree with each other: a banner offering per-category choice while the policy says consent is not collected will fail the first audit it meets. This tool writes the policy text only. The banner is code you still have to add.

What it cannot know

Only what you type. It has no view of your database schema, your vendor list or the analytics script in your page template. If a form on your site collects a phone number and you did not mention it, the draft will be silently wrong on that point. The generated document carries a notice saying so, positioned first, because the person who eventually reads your policy should not have to guess where it came from.