Generate a bulletproof, jurisdiction-aware privacy policy for any business or product, usable by a non-lawyer founder and trusted by a lawyer. The whole point of this skill is correctness without hallucination: a fabricated statutory citation or a clause that doesn't match the user's real practices is worse than no policy at all.
references/) or a live
legal-data-hunter lookup. If you're unsure of a specific, name the law in plain terms ("California's
CCPA/CPRA," "the EU GDPR") and describe the right functionally — or omit it. Uncertain → omit or mark
[VERIFY], never guess.[GAP — confirm before publishing]
marker, never a guess.Ask (or infer): QUICK (non-lawyer: only the must-ask questions, batched, smart defaults pre-filled, ~10
answers) or EXPERT (lawyer/thorough: full questions, clause-level control, citations, full reconciliation).
→ Read references/intake-questionnaire.md for both flows.
Ask intake Groups 0–2 (product type → business identity → where users are located). Location is the law-selector. If "international / unknown," apply the strictest-common-denominator (GDPR + CCPA + COPPA). This ordering is what prevents generic boilerplate.
Work Groups 3–17 of references/intake-questionnaire.md. Batch questions; offer the smart default so the
user can accept with "yes." Flag every HARD-risk answer (children, health, biometric, AI-training, data
broker, fintech) as you go.
For each jurisdiction/topic in scope, pull the requirements from the matching reference file — never from memory:
references/jurisdictions-eu-uk.md — GDPR Art 13/14 checklist, lawful bases, rights, transfers, cookies, UK/DUAA, children ages, enforcement.references/jurisdictions-us.md — CCPA/CPRA contents + the two mandatory links + Notice at Collection, ~20 state laws, COPPA, GPC, ADMT, sector overlays, FTC §5.references/jurisdictions-global-mena.md — Brazil, Canada/Quebec, Australia, India, China, Japan/Korea/SA/Switzerland + UAE/DIFC/ADGM/Saudi/Bahrain/Qatar/Egypt/Turkey + cross-jurisdiction synthesis.references/platform-cookies-ai.md — when a policy is contractually forced; Apple/Google app-store rules; per-tool disclosures (GA, AdSense, Meta Pixel, Stripe, PayPal, Mailchimp, Cloudflare, session-recording, A/B); cookies/CMP/TCF/GPC/Consent-Mode; AI/LLM + EU AI Act Art 50 + ADM.references/sector-and-special-products.md — HIPAA/HBNR/MHMDA, GLBA, FERPA/SOPIPA, BIPA/Texas CUBI, Chrome extensions, IoT SB-327, GDPR Art 32/33/34 security/breach + US breach laws.legal-data-hunter MCP is connected (HAQQ's 230-jurisdiction tool),
use it to verify or fetch a jurisdiction-specific requirement with an inline citation — especially for a
jurisdiction not fully covered in the pack, or for the latest amendment. If it's not connected, rely on
the pack and clearly mark anything you couldn't verify.Use the section order + modular clause library in references/structure-clauses-and-craft.md and the
fill-in backbone in assets/template-privacy-policy.md. Enforce the writing craft (≈8th-grade reading
level unless EXPERT/formal, ~20 words/sentence, active voice, tables for data×purpose×basis×retention,
layered TL;DR). Use the DO phrasing; never the banned phrasing. Render jurisdiction-specific sections
(e.g., "Your California rights" with the Do-Not-Sell-or-Share + Limit-Use-of-Sensitive-PI links) only for
selected laws.
Run the 12-point checklist in references/edge-cases-failure-modes-qa.md §3 on your own draft. In
particular:
cite-guard is
available, run it here.[GAP].Output: the policy (in the requested language(s), RTL-aware for Arabic per structure-clauses-and-craft.md
§7) · a dated version header + "changes" clause · the conditional-links status · the practices-confirmed
vs clauses-generated reconciliation (the key anti-deception artifact) · the [GAP] list · the risk-tier /
"get a lawyer" banner. Default output format: Markdown (offer HTML on request). Recommend human review of any
machine translation.
A privacy policy is necessary but not sufficient. Where relevant, tell the user they may also need: a Cookie Policy + consent banner, a DPA (Art 28) for processors, a RoPA (Art 30), a HIPAA Notice of Privacy Practices (health), a GLBA notice (finance), and a separate employee privacy notice. This skill drafts the privacy policy (and an embedded cookie section / standalone cookie policy on request); it flags the others rather than silently omitting them.
Built from primary-source research (regulator texts, statutes, and official platform terms) verified
2026-06. Sources are cited inside each references/ file. AGPL-3.0. Informational template — not legal advice.