Terms & Privacy Starter
What it does
Builds the first draft of a terms-of-service and privacy policy for a small site, app, or newsletter — based on what your thing actually does with people’s data, not copy-pasted boilerplate from a bigger company whose terms don’t match your reality.
When to use it
- Launching a site, product, or newsletter that collects anything (even just emails)
- Your current policy is copied from a template and describes features you don’t have
- You added analytics, payments, or AI processing and the old policy doesn’t mention it
The skill
Act as a careful drafter of website terms and a privacy policy,
producing FIRST DRAFTS for professional review. Rules: describe
only what I tell you the product actually does — a policy that
overpromises ("we never share data") or overclaims is worse than
none; never invent compliance claims (no "GDPR compliant" or
"CCPA compliant" badges — name the obligations, let a professional
confirm); plain language a normal user could read.
Before drafting, ask me:
- What the site/app/newsletter does, and who it's for
- Every piece of data collected (emails? analytics? payments?
uploads? AI processing of user content?) and which third-party
tools touch it (hosting, analytics, payment, email provider)
- Where I'm based and where my users mostly are
- Whether anyone under 18 could realistically be a user
Then draft:
1. TERMS OF SERVICE: what the service is, what users may/may not do,
payments and refunds if any, my right to change or discontinue,
liability stated plainly and flagged for review, how disputes are
raised.
2. PRIVACY POLICY: what's collected, why, who processes it (name the
actual tools I listed), how long it's kept, how users get their
data or delete it, contact for questions.
3. A "FLAG FOR PROFESSIONAL" list: every point where my jurisdiction
or my users' jurisdictions impose specific requirements
(EU/GDPR-type rights, cookie consent, minors' data), stated as
"verify this," never as invented rule text.
End with: "These are drafts to bring to a professional, not a
substitute for one — data law depends on where your users are."
Example output
[TO FILL AFTER TESTING]
Tweaks
- The honesty rule cuts both ways: don’t let the draft promise privacy practices you don’t actually follow — that’s the version that creates liability
- Re-run this whenever you add a tool that touches user data; the policy describes the system, and the system changed
- A newsletter with one signup form needs a page, not a novel — tell it to keep the scale honest too
The honest line
Boilerplate terms describe someone else’s product. A wrong policy is a liability dressed as a checkbox. Draft yours from what you actually do, then have a professional check the jurisdiction-specific parts — especially if you have EU users.