Privacy Policy Generator

Draft a privacy policy from what your site actually collects: forms, comments, analytics, cookies, orders and accounts, with GDPR and CCPA sections.

Live output

Enable JavaScript to customise; default output below.

A real, monitored address. A privacy request has a legal deadline attached to it.

Required for a GDPR controller. Leave empty to omit the line.

Live preview privacy-policy.html
<!-- A starting point, not legal advice. Read every line and change what is not true of your site. -->
<h1>Privacy Policy</h1>

<p><em>Last updated: 2026-01-01</em></p>

<p>This policy explains what Acme Ltd collects when you use https://example.com, why, and what you can ask us to do about it.</p>

<h2>Who we are</h2>

<p>Acme Ltd operates https://example.com. You can reach us about anything in this policy at <a href="mailto:[email protected]">[email protected]</a>.</p>

<h2>What we collect and why</h2>

<h3>Contact forms</h3>

<p>When you send us a message we receive the name, email address and any other details you type into the form, together with the message itself. We use them to reply to you and to keep a record of the conversation. We do not use form submissions for marketing unless you ask us to.</p>

<h3>Comments</h3>

<p>When you leave a comment we store the comment, the name and email address you give, your IP address and your browser's user agent string. The IP address and user agent help us detect spam. Comments and their metadata may be checked by an automated spam detection service.</p>

<h3>Analytics</h3>

<p>We use Google Analytics to understand which pages people read and how they arrive. It collects information about your visit, which may include your approximate location, device and browser, and the pages you view. We use it in aggregate to decide what to write and what to fix.</p>

<h3>Cookies</h3>

<p>Cookies are small files stored by your browser. We use them to keep you signed in, to remember preferences, and, where you have agreed to it, for analytics. You can delete or block cookies in your browser settings; some parts of the site will stop working if you block the necessary ones.</p>

<h2>How long we keep it</h2>

<p>We keep contact details for 24 months after our last conversation with you, unless you ask us to remove them sooner. Comments and their metadata are kept indefinitely so that follow-up comments can be recognised and approved automatically.</p>

<h2>Who we share it with</h2>

<p>We do not sell your personal information. We share it only with the services we need to run the site, such as Google Analytics, and where the law requires us to.</p>

<h2>Your rights (UK and EU)</h2>

<p>If you are in the UK or the European Economic Area, you have the right to ask us for a copy of the personal data we hold about you, to have it corrected or deleted, to object to how we use it, and to ask us to restrict our use of it. You also have the right to receive the data you gave us in a portable form.</p>

<p>Ask by emailing <a href="mailto:[email protected]">[email protected]</a>. We will respond within one month. If you are unhappy with our response you can complain to the data protection authority in your country.</p>

<h2>Children</h2>

<p>This site is not aimed at children, and we do not knowingly collect information from anyone under 13. If you believe a child has given us personal information, email us and we will delete it.</p>

<h2>Changes to this policy</h2>

<p>If this policy changes we will update the date at the top. Significant changes will be announced on the site.</p>

Output is valid and updates as you type.

Draft a privacy policy from what your site actually collects, rather than from a template that lists everything. It is a starting point for a lawyer or a careful read, not legal advice.

How to use

  1. Tick only what is true. A policy describing collection you do not do is as wrong as one that leaves out collection you do, and the second kind is what regulators act on.
  2. Name your actual providers. “A third-party analytics service” helps nobody; “Google Analytics” tells a visitor what to look up.
  3. Give a real, monitored email address. A subject access request under GDPR starts a one month clock whether or not anyone is reading that inbox.
  4. Say a retention period you will honour. “As long as necessary” is the phrase everyone writes and nobody can act on.
  5. Read every line before publishing. This is a draft based on what you ticked, and only you know whether it matches what your site does.

Example

The retention section is where most templates go vague:

<h2>How long we keep it</h2>

<p>We keep contact details for 24 months after our last conversation with you,
unless you ask us to remove them sooner. Order and payment records are kept for
as long as tax and accounting rules require, which is usually longer.</p>

A specific period is something you can build a deletion routine around. A vague one means the data is kept forever by default.

Pitfalls

  • This is a draft, not legal advice. Privacy law is jurisdictional and changes; a lawyer in your country is the only way to be sure.
  • GDPR applies based on where your visitors are, not where you are. A site in the United States with UK readers is in scope.
  • A policy that does not match reality is worse than none: it is a documented statement you can be held to.
  • Embedded content from other sites collects data as if the visitor had gone there. That belongs in the policy even though you wrote none of it.
  • Cookie consent is a separate obligation in the UK and EU. A policy that mentions cookies does not replace asking before setting non-essential ones.
  • Naming a processor means keeping the list current. Swapping analytics providers without updating the policy is a small, real inaccuracy.
  • CCPA has revenue and volume thresholds. Including the section when it does not apply is harmless; assuming it applies instead of checking is not.
  • WordPress has a built-in privacy policy draft under Settings, Privacy, which plugins add their own sections to. Check it before writing from scratch.

Compatibility

The output is plain HTML that pastes into the WordPress block editor, where it converts to blocks. It covers GDPR (UK and EU), CCPA (California) and the general disclosure expectations of most other regimes, but it is written in plain language rather than to any single statutory template. The tool runs entirely in your browser: nothing you type is uploaded.

Frequently asked questions

Is this legally sufficient?
It is a well-structured draft. Whether it is sufficient depends on your jurisdiction, your business and what you actually do with data. Have it reviewed.
Does GDPR apply to me?
If you have visitors in the UK or EU and you collect anything identifying, including IP addresses through analytics, assume yes.
Do I need a cookie banner too?
In the UK and EU, for anything beyond strictly necessary cookies, yes. The policy explains; the banner asks.
What about my plugins?
Several WordPress plugins add their own suggested privacy text under Settings, Privacy. Check there and fold in anything relevant.
How often should I update it?
Whenever what you collect changes, and whenever you add or remove a service that handles personal data.
Weekly drops

New tools, when there are new tools

One email when something worth using ships. No schedule to fill, so no filler.

Your address goes nowhere else, and one click unsubscribes.