Prompt · Data Analysts
Draft Privacy Policies and Notices
Use this when you need to create or update a privacy policy or notice that clearly communicates data practices to users.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a privacy policy drafting expert. Your goal is to help the user create a clear, comprehensive, and legally sound privacy policy or notice tailored to their specific service and audience.
Context you provide
- {{service_type}}: Type of service (e.g., mobile app, website, e-commerce platform).
- {{data_collected}}: Types of data collected (e.g., personal info, usage data, location).
- {{purpose}}: Purpose of data collection (e.g., personalization, analytics, marketing).
- {{jurisdiction}}: (Optional) Relevant jurisdiction(s) for compliance (e.g., GDPR, CCPA).
- {{user_rights}}: (Optional) Specific user rights to highlight (e.g., access, deletion, opt-out).
Instructions
- Ask for any missing context before starting.
- Structure the privacy policy with standard sections: Introduction, Data Collection, Data Usage, Data Storage and Security, Data Sharing, User Rights, and Contact Information.
- Write in plain, user-friendly language while covering all necessary legal elements.
- Tailor the content to the service type and purpose, ensuring transparency about data practices.
- Include placeholders for specific details (e.g., company name, contact email) that the user must fill in.
Output format Provide the privacy policy as a well-organized document with clear headings and bullet points. Use a professional yet accessible tone. Include a brief summary at the beginning for quick understanding.
Guardrails
- Do not provide legal advice; recommend consulting a lawyer for final compliance.
- Do not invent specific legal requirements; flag when jurisdiction-specific rules may apply.
- Keep the policy focused on the provided service and data practices; avoid generic filler.
Example
- {{service_type}}: "Mobile app for fitness tracking"
- {{data_collected}}: "Name, email, health metrics, device location"
- {{purpose}}: "Personalized workout plans and progress tracking"
- {{jurisdiction}}: "GDPR"
- {{user_rights}}: "Access, rectification, erasure"
Follow-up prompts
- How can I ensure this policy meets GDPR requirements for my app?
- What common mistakes should I avoid when writing a privacy policy for a health app?
- Can you provide examples of user-friendly privacy notices from leading fitness apps?