| name | privacy-policy-stephane-boghossian |
| version | 1.0.0 |
| description | A zero-hallucination privacy-policy generator that takes anyone — non-lawyer founder to lawyer — from a guided intake to a publishable, jurisdiction-aware privacy policy. Jurisdiction-first: it detects which laws apply from where your users are, then drafts only the required clauses — GDPR/EU + UK, US (CCPA/CPRA, ~20 state laws, COPPA, sector overlays), and global/MENA (LGPD, Quebec Law 25, India DPDP, China PIPL, UAE/DIFC, Saudi PDPL), plus app-store, cookies, and AI/EU AI Act disclosures. Its rule: state only what you confirm; never invent a statute, citation, fine, or date — every claim is source-cited and QA-gated. Not legal advice. |
| license | AGPL-3.0 |
| keywords | ["privacy policy","privacy notice","GDPR","CCPA","CPRA","data protection","cookie policy","COPPA","app privacy","LGPD","PDPL"] |
| language | English |
| triggers | ["write a privacy policy","create a privacy policy","generate a privacy policy","privacy policy for my app/website/SaaS/store","GDPR privacy policy","CCPA/CPRA privacy notice","I need a data protection notice"] |
| metadata | {"author":"Stephane Boghossian","license":"agpl-3.0","version":"2026-06-30"} |
Privacy Policy Generator
Generate a bulletproof, jurisdiction-aware privacy policy for any business or product, usable by a
non-lawyer founder and trusted by a lawyer. The whole point of this skill is correctness without
hallucination: a fabricated statutory citation or a clause that doesn't match the user's real practices
is worse than no policy at all.
⚖️ The prime directive (read this first, never break it)
- State ONLY what the user confirms they actually do. A privacy policy is a set of enforceable
representations (FTC §5; see the OkCupid/Match 2026 and Gateway Learning cases in the reference pack).
Saying more than is true is the #1 legal failure. Never default-in a flattering or risk-adding clause.
- Never invent law. Do not generate a statute/section number, a fine amount, an effective date, or a
"the law requires X" claim unless it traces to the bundled reference pack (
references/) or a live
legal-data-hunter lookup. If you're unsure of a specific, name the law in plain terms ("California's
CCPA/CPRA," "the EU GDPR") and describe the right functionally — or omit it. Uncertain → omit or mark
[VERIFY], never guess.
- Confirm-don't-assume. A clause renders only if a confirming intake answer exists. Smart defaults are
allowed ONLY for protective/negative clauses (no children, no selling, standard security framing, today's
date, strictest-common-denominator). Anything unanswered → a visible
[GAP — confirm before publishing]
marker, never a guess.
- This is not legal advice. Always include the disclaimer; INSIST on a lawyer for high-risk cases (§ workflow step 6).
Workflow
Step 1 — Pick the mode
Ask (or infer): QUICK (non-lawyer: only the must-ask questions, batched, smart defaults pre-filled, ~10
answers) or EXPERT (lawyer/thorough: full questions, clause-level control, citations, full reconciliation).
→ Read references/intake-questionnaire.md for both flows.
Step 2 — Compute the applicable-law set FIRST (jurisdiction-first)
Ask intake Groups 0–2 (product type → business identity → where users are located). Location is the
law-selector. If "international / unknown," apply the strictest-common-denominator (GDPR + CCPA + COPPA).
This ordering is what prevents generic boilerplate.
Step 3 — Gather practices (only the questions the selected laws require)
Work Groups 3–17 of references/intake-questionnaire.md. Batch questions; offer the smart default so the
user can accept with "yes." Flag every HARD-risk answer (children, health, biometric, AI-training, data
broker, fintech) as you go.