Answer a few questions about your site and get a clean, readable privacy policy, with the GDPR and CCPA/CPRA clauses the paid tools hide behind a paywall. Copy it or download it as HTML or text. No signup, no branding on your policy.
Almost every website needs a privacy policy: the moment you run analytics, drop a cookie, or collect a name and email through a form, you are processing personal data. This tool builds a clean, readable policy from your own inputs, and it conditionally adds the GDPR and CCPA/CPRA sections that the free tiers of the paid tools tend to lock away.
You tell us your company name, website, and a contact email, then check the boxes for what your site actually does (analytics, cookies, forms, email marketing, ads, payments, embeds). The generator assembles only the sections that apply to you, so you are not stuck with boilerplate about credit-card processing on a five-page brochure site. If you serve EU/UK or California visitors, it folds in the GDPR data-subject rights and the CCPA/CPRA "Do Not Sell or Share" language. Everything runs in your browser, so nothing you type is uploaded anywhere.
Termly runs around $14 to $20 a month, and its free version stamps its own branding on your policy. iubenda runs $6 to $100 a month, and its free tier blocks custom text and adds branding too. TermsFeed charges per document. Ours is free, requires no signup, downloads as clean HTML or text with no logos or watermarks, and includes the GDPR and CCPA clauses the free tiers withhold. The one thing the paid tools offer that a static template cannot is automatic updates as laws change, which is exactly what our Pro version handles.
A copied or generic policy can be worse than none, because it may promise things you do not do or omit disclosures you are legally required to make. Regulators, app stores, ad networks, and payment processors all expect a policy that matches your actual data practices. Generating one from your real inputs keeps it honest, and updating the "Last updated" date every time your practices change keeps it credible.
The Pro version keeps your privacy, terms, cookie, and accessibility policies current automatically and hosts them on your site.
Get early access, book a free call →Four fields and ten checkboxes drive everything. You enter your company or site name, your website address, a contact email, and optionally the state or country whose law governs. Then you tick what the site actually does: analytics, cookies, contact forms, email marketing, ads and retargeting, e-commerce and payments, third-party embeds, EU and UK visitors, California visitors, and whether children may use the site. Each box switches specific clauses on. Tick ads and the cookie section gains advertising-cookie language while the sharing section names retargeting platforms. Leave e-commerce unticked and there is no payments section at all.
Some sections always print: what is collected, how it is used, how it is shared, retention, security, children's privacy, third-party links, changes to the policy, and contact. The GDPR block lists seven data-subject rights and the usual legal bases. The CCPA and CPRA block lists six consumer rights plus a Do Not Sell or Share section. A disclaimer sits at the top. Copy the text or download it as HTML or plain text, with no branding, watermark, or backlink to us inside it. No AI writes any of this. The clauses are pre-written and assembled in your browser.
Read the limits before you publish. This is a template, not legal advice, and no attorney has reviewed it for your business. The generator never fetches your site, so it cannot verify that the boxes you ticked match what your pages actually load. It does not cover sector rules such as HIPAA or GLBA, does not write your terms of service or cookie banner, and cannot know when a law changes, which is the one thing a paid subscription genuinely buys you. Keeping policies current is part of ongoing website maintenance.
No. It never fetches your site and never sees your tag manager, so the policy is only as accurate as the boxes you tick. If you are unsure what is loading, check your page source and your analytics and ad accounts first. A policy that describes practices you do not have is a problem of its own, and so is one that omits a tracker you do run.
It is a reasonable first draft for a small brochure or lead-generation site, and it is unbranded, so it is yours to edit freely. It is still not legal advice, and the tool cannot know your industry's rules. Have a qualified attorney review it before it goes live, especially if you touch health, financial, or children's data, and regenerate it whenever you add a tracker, a store, or a new form.