Add Privacy Policy & Terms Pages to Any AI-Built Website

Add clear Privacy Policy and Terms pages to your website, document the services and data your site actually uses, link the pages correctly, and remove misleading boilerplate before launch.

Roadmap & Resources

Audit What the Website Actually Collects & Uses

Audit the Website First

Do not start by asking AI to generate a generic privacy policy. First inspect the real website.

Privacy & Terms Readiness Audit

Identifies the framework, business/site name, existing contact info, and every feature that might collect or send data — forms, accounts, analytics, ad pixels, cookies, payment providers, bookings, embeds, email providers, databases, uploads, user content, external APIs — plus any existing legal pages or placeholder legal text. Changes nothing, invents nothing, makes no compliance claims, and reports what belongs in the Privacy Policy and Terms plus exactly what business information is still missing.

Review this website specifically for preparing accurate Privacy Policy and Terms pages. Do not change anything yet. Identify: - the framework and project type - business/site name - public contact information already shown - contact forms - newsletter forms - account creation/login - authentication providers - analytics - advertising/tracking pixels - cookies or local storage - payment providers - booking services - embedded maps - videos or third-party embeds - email providers - databases - file uploads - user-generated content - external APIs - any other third-party service that receives user or visitor data For each service or feature, identify: - what information appears to be collected - why the website uses it - whether the information goes to a third-party provider - whether the feature is optional or essential Also identify: - any existing Privacy Policy - Terms / Terms of Service - Cookie Policy - legal links in the footer - consent text near forms - placeholder or obviously generic legal text Do not expose secrets. Do not invent business details. Do not make legal-compliance claims. Finish with: 1. Data/features that should be reflected in the Privacy Policy 2. Third-party services that should be disclosed 3. Topics that may belong in the Terms 4. Missing business information I need to provide 5. Existing legal pages or links that can be reused

Provide the Missing Business Details

Before generating the pages, confirm information such as:

- Business/site name

- Contact email

- Country or business location, where appropriate

- What the website provides

- Whether users create accounts

- Whether the site accepts payments

- Whether refunds/cancellations apply

- Whether users upload or submit content

IMPORTANT

Do not let the AI invent missing company names, addresses, refund rules, or legal jurisdictions.

Create the Privacy Policy

What the Policy Should Cover

The Privacy Policy should reflect what the website actually does.

For a Simple Business Website

This may cover contact-form submissions, newsletter subscriptions, analytics, cookies, embedded services, payment providers, and how visitors can contact the business.

For a Web App

It may also need to describe accounts, user data, uploaded files, authentication, databases, and service providers.

Draft the Privacy Policy

Draft the Privacy Policy

Drafts a Privacy Policy page using the completed audit and confirmed business details — reflects only services/data actually present, plain English, includes cookies/accounts/payments language only if genuinely used, and is added as a real page in the project's existing layout and typography. Never invents legal entities, addresses, retention periods, or compliance certifications, never claims GDPR/CCPA compliance, never presents itself as legal advice, never deploys, and answers Privacy Policy draft: READY FOR OWNER REVIEW or NEEDS INFORMATION with exactly what's missing.

Create a draft Privacy Policy for this website using the audit we completed and the confirmed business information below. Business/site name: [BUSINESS NAME] Contact email: [CONTACT EMAIL] Business country/location if relevant: [LOCATION] Requirements: - reflect only services and data practices actually present in this website - use plain, understandable English - explain what information may be collected - explain why that information is used - identify relevant third-party services where appropriate - explain contact options for privacy-related questions - include cookies/tracking only if the website actually uses them - include account/user-data language only if the website actually has accounts - include payment-provider language only if payments exist Do not: - invent legal entities, addresses, retention periods, or compliance certifications - claim the website is GDPR, CCPA, or otherwise legally compliant - include services the website does not use - copy generic clauses that contradict the actual website - present this draft as professional legal advice Add the policy as a real website page using the project's existing page layout and typography. Preserve the website design. Do not deploy anything automatically. Finish with: **Privacy Policy draft: READY FOR OWNER REVIEW / NEEDS INFORMATION** If information is missing, list exactly what I need to confirm.

Review the Draft

Read it yourself before publishing. Pay special attention to:

Services listed

Contact details

What data is collected

Payment/analytics providers

Statements about how long information is stored

Statements about user rights

Jurisdiction-specific language

IMPORTANT

For businesses with regulated data, complex international operations, children, healthcare, finance, or other higher-risk activities, a generic AI-generated policy should not be treated as a substitute for professional legal review.

Add Terms & Legal Links

Draft the Terms

Now create Terms appropriate to what the website actually provides. A basic informational business website needs much simpler Terms than a SaaS platform or marketplace.

Draft the Terms of Use

Drafts a Terms/Terms of Use page covering only topics that genuinely apply — acceptable use, content, IP, accounts, payments, subscriptions, refunds/cancellations, user-submitted content, external links — using the real website and confirmed business info. Never invents refund rules, cancellation periods, warranties, governing law, arbitration, registration details, age requirements, or liability promises; marks anything needing an owner decision instead of guessing; adds the page in the site's existing design; never deploys; and answers Terms draft: READY FOR OWNER REVIEW or NEEDS INFORMATION with what needs a decision.

Create a draft Terms / Terms of Use page for this website. Use the actual website functionality and confirmed business information. Cover only topics that genuinely apply, such as: - acceptable use of the website - website content - intellectual property - contact/service enquiries - user accounts, if they exist - payments, if they exist - subscriptions, if they exist - cancellations/refunds only if I provide the actual policy - user-submitted content only if supported - external links/services Do not invent: - refund rules - cancellation periods - warranties - governing law - arbitration requirements - company registration details - age requirements - liability promises If one of those topics requires a business decision that I have not provided, mark it clearly for review rather than making it up. Use plain English and keep the page appropriate for this specific website. Add the page using the website's existing design. Do not deploy automatically. Finish with: **Terms draft: READY FOR OWNER REVIEW / NEEDS INFORMATION** List anything that requires my decision before publishing.

Add the Legal Links

The pages should be easy to find. A common footer setup is Privacy Policy and Terms. If the website has a Cookie Policy or another genuinely relevant page, include it as well.

Add Legal Links to Navigation

Adds the new Privacy Policy and Terms pages to the site's legal navigation — footer by default unless another legal-links area already exists — with clear labels, working desktop/mobile links, no duplicate legal navigation, and no clutter added to the primary nav. Also points any existing form/signup consent wording at the real new pages, without adding a consent checkbox unless the workflow genuinely needs one, then runs the production build without deploying.

Add the existing Privacy Policy and Terms pages to the website's legal navigation. Prefer the footer unless the current design has another established legal-links area. Requirements: - preserve the existing footer design - use clear labels - make the links work on desktop and mobile - avoid duplicate legal navigation - do not clutter the primary navigation unnecessarily Also review forms and signup areas. If a form already contains privacy/consent wording, make sure its Privacy Policy link points to the new real page. Do not add consent checkboxes automatically unless the specific workflow actually requires one. Run the production build afterward. Do not deploy automatically.

Check Everything Before Publishing

Run the Final Consistency Audit

Now verify that the legal pages match the real website.

Final Legal Pages Audit

Verifies every third-party service named in the Privacy Policy is genuinely used and nothing important was omitted, contact info is correct, no placeholder business info or fake entity/address remains, no unsupported compliance claim appears, payment/account/newsletter/analytics language matches the real setup, legal links work on desktop and mobile, form links point to the correct URL, both pages are readable and responsive, and the production build succeeds — flags anything needing a real business/legal decision, never rewrites for style, never deploys, and answers Legal pages status: READY FOR OWNER REVIEW or NOT READY.

Run a final consistency audit of the Privacy Policy, Terms, and the actual website. Verify: - every third-party service named in the Privacy Policy is genuinely used - important data-collecting services used by the website are not accidentally omitted - contact information is correct - no placeholder business information remains - no fake legal entity or address was invented - no unsupported compliance claim appears - payment language matches the actual payment setup - account/authentication language appears only if accounts exist - newsletter/marketing language matches the actual website - analytics/tracking language matches the actual implementation - legal links work - footer links work on mobile - forms linking to the Privacy Policy use the correct URL - both pages are readable and responsive - page titles and metadata are sensible - the production build succeeds Flag anything that requires a real business or legal decision instead of guessing. Do not rewrite clauses merely for stylistic preference. Do not deploy anything automatically. Finish with: **Legal pages status: READY FOR OWNER REVIEW / NOT READY** If NOT READY, list only the remaining issues.

Before Publishing

Read both pages yourself. Check that they describe your actual business and website, not an imaginary generic company. Then publish them with your normal workflow.

After Deployment

After deployment:

Open Privacy Policy. Open Terms. Test both on mobile. Test every footer link. Test any Privacy Policy links near forms. Revisit the pages whenever you materially change how the website collects data or accepts payments.

NOTE

These pages are now part of the website, but they should still be treated as drafts that reflect your actual setup — not as a guarantee of legal compliance.