Privacy Policy Template
Use this as the preferred structure for PRIVACY.md. Keep text specific to repository evidence. Use TODO(confirm): for unknown business facts.
# Privacy Policy
Effective date: TODO(confirm): YYYY-MM-DD
This Privacy Policy explains how TODO(confirm): [legal entity/product] ("we", "us", or "our") collects, uses, shares, and protects personal data when you use TODO(confirm): [product/site/app].
This draft is provided for review and is not legal advice.
## 1. Who We Are
- Product/service: TODO(confirm)
- Controller/operator: TODO(confirm)
- Website: TODO(confirm)
- Contact: TODO(confirm)
- Postal address, DPO, or EU representative: TODO(confirm, if applicable)
## 2. Scope
Describe the covered surfaces: website, SaaS app, API, CLI, mobile app, workspace, browser extension, docs, support, or marketing pages.
## 3. Personal Data We Collect
Group by source:
- Data you provide: account profile, contact details, workspace data, uploaded content, support messages, billing details.
- Data collected automatically: logs, IP address, device/browser data, cookies/local storage, analytics events, usage events, crash reports.
- Data from third parties: OAuth providers, payment processors, integrations, imported workspace data.
- AI data, if applicable: prompts, files, outputs, metadata, model/provider routing.
Do not include categories unsupported by evidence.
## 4. How We Use Personal Data
Map purposes to legal bases where GDPR or similar regimes may apply:
| Purpose | Data | Legal basis |
| --- | --- | --- |
| Provide and secure the service | TODO(confirm) | Contract / legitimate interests |
| Process payments | TODO(confirm) | Contract / legal obligation |
| Improve the service | TODO(confirm) | Legitimate interests / consent |
| Send marketing | TODO(confirm) | Consent / legitimate interests |
## 5. Cookies, Local Storage, And Tracking
Describe essential cookies/session storage, analytics cookies, marketing cookies, local storage, consent controls, and browser controls. If no cookie audit was possible, mark unknowns with `TODO(confirm):`.
## 6. Sharing And Processors
List verified provider categories and providers from the evidence matrix. Explain that providers process data for service operation, payment, hosting, analytics, support, security, or AI features as applicable.
## 7. International Transfers
Describe known processing locations and transfer safeguards. Use `TODO(confirm):` for unknown hosting region, SCCs, adequacy decisions, or provider safeguards.
## 8. Retention
Cover account data, billing/tax records, logs, backups, support messages, analytics, and deleted accounts. Do not invent durations.
## 9. Your Rights And Choices
Cover access, correction, deletion, portability, objection, restriction, consent withdrawal, marketing opt-out, cookie controls, and complaint to a supervisory authority where applicable.
## 10. Security
Describe reasonable safeguards only at the level supported by evidence. Avoid naming certifications or encryption details unless verified.
## 11. Children
State the minimum age and whether the service knowingly collects children's data. Use `TODO(confirm):` if unknown.
## 12. AI Features
Include only if relevant. Explain what is sent to AI providers, why, and what user controls exist. Do not claim no training/retention unless verified.
## 13. Changes To This Policy
Explain how updates are posted and whether users are notified of material changes.
## 14. Contact
Provide privacy/support/legal contact details or `TODO(confirm):`.