WoluTools

Legal · Browser tool

Privacy policy generator for websites and apps

Answer a questionnaire about the data you collect, your cookies, analytics and service providers. You get a GDPR and CCPA draft in Markdown and HTML to check and have reviewed before you publish.

Freeno account · no limit · runs in your browser, nothing is uploaded

  • Sections appear only when your answers call for them
  • Copy the text or download it as .md or .html
  • A review notice sits at the top of the draft until you delete it

Step 1 of the questionnaire

Where are your users?

Where your users are
Cookies and analytics

Sections these answers add to your draft

  • Your rights under the GDPRIncludedLeft out
  • California residents (CCPA and CPRA)IncludedLeft out
  • Cookies and similar storageIncludedLeft out
  • AnalyticsIncludedLeft out

Every draft also has who you are, what the policy covers, what you collect and why, retention, children, security, changes and contact details.

The full form opens next. Set these answers there under “Which law applies” and “Cookies and analytics”, then add your organisation, the data you collect and your providers.

What you get: a sample draft

Built from the example answers that come pre-filled in the form, for a fictional company. Replace them with your own before you use the text.

Example answers

Publisher
Northwind Analytics, a fictional company in Ireland
Users
European Economic Area only
Data collected
Account, billing, support messages, usage, device and log data
Cookies
Strictly necessary, preferences, analytics; banner with per-category choice
Analytics
Yes, IP addresses shortened before storage
Providers
4, some with access from the United States; standard contractual clauses

Sections in the draft

Unnumbered first: “Read this before you publish it”, the review notice.

  1. Who we are
  2. What this policy covers
  3. What we collect and why
  4. Cookies and similar storage
  5. Analytics
  6. Who else handles your data
  7. Data leaving the EEA
  8. How long we keep things
  9. Children
  10. Your rights under the GDPR
  11. How we protect the data
  12. Changes to this policy
  13. Getting in touch

No California section, because the users are in the EEA only.

Read an excerpt of the sample draft

2. What this policy covers

This policy applies to Northwind Dashboard and to the correspondence we exchange with you about it. Where we link to something run by someone else, that service is governed by its own policy and we have no say in how it handles your data.

The service is offered to people in the European Economic Area. Rights described below are the ones the GDPR grants.

3. What we collect and why (first row)

Data
Account details: name, email address, password hash
Purpose
Creating your account and letting you sign in
Lawful basis
Performance of a contract, Article 6(1)(b)
Retention
While the account exists, then 30 days

7. Data leaving the EEA

Some of the providers listed above process data outside the European Economic Area. We rely on the European Commission’s standard contractual clauses, together with a transfer impact assessment for each recipient.

From questionnaire to policy

  1. 1

    Answer the questions

    Say where your users are, what data you collect and why, which cookies and analytics you use, which providers handle data for you, and which security measures you can honestly claim.

  2. 2

    Read the draft as it forms

    The draft updates while you type. It uses standard sections: data collected, purpose, legal basis, providers, retention, user rights and contact details. Sections you have no answer for are left out rather than filled with boilerplate.

  3. 3

    Copy or download

    Copy the Markdown or HTML, or download a .md or .html file, and paste it into your CMS or static site. Your answers are not stored, so keep a note of them for the next update.

Drafting a privacy policy from your own answers

What you answer

The questionnaire asks what data you collect, which analytics, payment and other providers you use, where your users are, and which cookies you set. The draft covers GDPR for the EU and EEA, UK GDPR for the United Kingdom, and CCPA and CPRA for California. It runs in your browser, with no account and no job limit.

What you get back

A draft in Markdown and plain HTML, with sections for the data collected, why it is processed and on what legal basis, providers, retention, user rights and contact details. A California section is added when you say you have US users. If you tick that you have appointed a data protection officer, their name and email go into the policy; if not, a GDPR draft says why you have none. Read each section against what your site really does.

What stays your job

The draft describes your cookies, but it is not a consent banner. Blocking cookies until a visitor agrees needs a separate script, and the banner and policy must match. This is a starting draft, not legal advice. Privacy law differs by country and changes often, so have a qualified lawyer review it before you publish.

Questions before you run it

Is this a substitute for a lawyer?

No. The generator produces a structured first draft based on your answers. It covers the sections regulators expect to see, but every business has unique circumstances. Have a qualified lawyer review the output before publishing it on your site.

Which regulations does the generator cover?

GDPR for the EU and EEA, UK GDPR for the United Kingdom, and CCPA/CPRA for California. Your answer to where your users are decides which of these sections the draft contains, and you can override that choice. The other questions are about your own data processing, so the draft describes what you actually do rather than a generic template.

Can I update the policy later?

Yes. Your answers are not stored, so keep the downloaded draft and a note of what you entered. When your data practices change, such as a new analytics tool or payment provider, fill in the questionnaire again and download a new draft.

What output formats are available?

Markdown and plain HTML. You can copy either one or download it as a .md or .html file. Both are structured with headings and sections, so you can paste the policy into your CMS or a static site without reformatting.

Does the generator handle cookie consent requirements?

It writes a cookie section that lists the categories you tick (strictly necessary, preferences, analytics, advertising) with a line on what each is for, plus a paragraph that matches your consent mechanism. It does not add a consent banner to your site; that needs a separate script, and the banner and policy have to agree.