Legal · Browser tool
Privacy policy generator for websites and apps
Answer a questionnaire about the data you collect, your cookies, analytics and service providers. You get a GDPR and CCPA draft in Markdown and HTML to check and have reviewed before you publish.
Freeno account · no limit · runs in your browser, nothing is uploaded
- Sections appear only when your answers call for them
- Copy the text or download it as .md or .html
- A review notice sits at the top of the draft until you delete it
What you get: a sample draft
Built from the example answers that come pre-filled in the form, for a fictional company. Replace them with your own before you use the text.
Example answers
- Publisher
- Northwind Analytics, a fictional company in Ireland
- Users
- European Economic Area only
- Data collected
- Account, billing, support messages, usage, device and log data
- Cookies
- Strictly necessary, preferences, analytics; banner with per-category choice
- Analytics
- Yes, IP addresses shortened before storage
- Providers
- 4, some with access from the United States; standard contractual clauses
Sections in the draft
Unnumbered first: “Read this before you publish it”, the review notice.
- Who we are
- What this policy covers
- What we collect and why
- Cookies and similar storage
- Analytics
- Who else handles your data
- Data leaving the EEA
- How long we keep things
- Children
- Your rights under the GDPR
- How we protect the data
- Changes to this policy
- Getting in touch
No California section, because the users are in the EEA only.
Read an excerpt of the sample draft
2. What this policy covers
This policy applies to Northwind Dashboard and to the correspondence we exchange with you about it. Where we link to something run by someone else, that service is governed by its own policy and we have no say in how it handles your data.
The service is offered to people in the European Economic Area. Rights described below are the ones the GDPR grants.
3. What we collect and why (first row)
- Data
- Account details: name, email address, password hash
- Purpose
- Creating your account and letting you sign in
- Lawful basis
- Performance of a contract, Article 6(1)(b)
- Retention
- While the account exists, then 30 days
7. Data leaving the EEA
Some of the providers listed above process data outside the European Economic Area. We rely on the European Commission’s standard contractual clauses, together with a transfer impact assessment for each recipient.
From questionnaire to policy
- 1
Answer the questions
Say where your users are, what data you collect and why, which cookies and analytics you use, which providers handle data for you, and which security measures you can honestly claim.
- 2
Read the draft as it forms
The draft updates while you type. It uses standard sections: data collected, purpose, legal basis, providers, retention, user rights and contact details. Sections you have no answer for are left out rather than filled with boilerplate.
- 3
Copy or download
Copy the Markdown or HTML, or download a .md or .html file, and paste it into your CMS or static site. Your answers are not stored, so keep a note of them for the next update.
Drafting a privacy policy from your own answers
What you answer
The questionnaire asks what data you collect, which analytics, payment and other providers you use, where your users are, and which cookies you set. The draft covers GDPR for the EU and EEA, UK GDPR for the United Kingdom, and CCPA and CPRA for California. It runs in your browser, with no account and no job limit.
What you get back
A draft in Markdown and plain HTML, with sections for the data collected, why it is processed and on what legal basis, providers, retention, user rights and contact details. A California section is added when you say you have US users. If you tick that you have appointed a data protection officer, their name and email go into the policy; if not, a GDPR draft says why you have none. Read each section against what your site really does.
What stays your job
The draft describes your cookies, but it is not a consent banner. Blocking cookies until a visitor agrees needs a separate script, and the banner and policy must match. This is a starting draft, not legal advice. Privacy law differs by country and changes often, so have a qualified lawyer review it before you publish.
Questions before you run it
Is this a substitute for a lawyer?
No. The generator produces a structured first draft based on your answers. It covers the sections regulators expect to see, but every business has unique circumstances. Have a qualified lawyer review the output before publishing it on your site.
Which regulations does the generator cover?
GDPR for the EU and EEA, UK GDPR for the United Kingdom, and CCPA/CPRA for California. Your answer to where your users are decides which of these sections the draft contains, and you can override that choice. The other questions are about your own data processing, so the draft describes what you actually do rather than a generic template.
Can I update the policy later?
Yes. Your answers are not stored, so keep the downloaded draft and a note of what you entered. When your data practices change, such as a new analytics tool or payment provider, fill in the questionnaire again and download a new draft.
What output formats are available?
Markdown and plain HTML. You can copy either one or download it as a .md or .html file. Both are structured with headings and sections, so you can paste the policy into your CMS or a static site without reformatting.
Does the generator handle cookie consent requirements?
It writes a cookie section that lists the categories you tick (strictly necessary, preferences, analytics, advertising) with a line on what each is for, plus a paragraph that matches your consent mechanism. It does not add a consent banner to your site; that needs a separate script, and the banner and policy have to agree.