Legal & Compliance

Verified against ChatGPT · 2026-08-11

Draft a privacy policy first pass structured around what you actually do with data, not a generic template

Produces a structured privacy policy draft built from your actual data practices — what you collect, why, who you share it with — rather than a boilerplate template with blanks filled in, flagged clearly as a draft for legal review.

ChatGPT (GPT-5.1)4 fillable variables
Scope for this category: Drafting, summarizing and organizing support only — every prompt states plainly that output is not legal advice and needs review by a qualified lawyer before being relied on or sent externally.

The prompt

Ready to copy — highlighted parts are example details you can swap.

Draft a first-pass privacy policy based on the actual data practices I describe below. This is a structured draft to give legal a real starting point, not a finished policy ready to publish.

WHAT DATA WE COLLECT
Name, email, IP address, and in-app usage analytics; no payment data (handled by a third-party processor).

WHY WE COLLECT IT
Email for account access and product updates; usage analytics to improve the product.

WHO WE SHARE IT WITH
Stripe for payment processing, Mixpanel for analytics; no data sold to advertisers.

WHERE OUR USERS ARE LOCATED
Mostly US-based, with a growing user base in the EU.

DRAFTING RULES
Build the policy from the specific data practices I described, not from a generic privacy policy template with placeholder categories swapped in — if I didn't mention collecting location data, don't include a location data section just because most policies have one; conversely, if I described something specific, give it real detail rather than folding it into a vague catch-all category. Structure it in the sections a reader and a regulator both expect: what's collected, why, how long it's retained (flag this as needing input if I didn't specify it), who it's shared with and why, what rights users have over their data, and how to contact us about it. Write the user-rights section based on what geography I gave you — flag explicitly that specific regional rights (like a right to deletion or data portability) depend on where users are located and which specific regulations apply, and that this needs confirmation rather than assuming a specific regulatory regime applies.

WHAT NOT TO DO
Do not name a specific privacy law or regulation as one we comply with (e.g., do not assert GDPR or CCPA compliance) unless I told you we've confirmed that — asserting compliance with a specific regulatory framework is a legal claim, and an inaccurate one here creates real liability. Do not invent a data retention period, a specific third-party vendor name, or a specific user rights process I didn't describe.

OUTPUT FORMAT
1. Draft privacy policy in standard sections (Data We Collect, Why We Collect It, Retention, Sharing, User Rights, Contact).
2. A separate list of every place you flagged missing information or a compliance claim that needs legal confirmation before publishing.
3. A closing note stating clearly this is a first-draft privacy policy built from the practices described, not a finished or legally reviewed document, and it must be reviewed by a qualified privacy lawyer — and checked against the specific regulations that actually apply to your users' locations — before publishing.

Customize

Optional — swap in your own details for the highlighted parts above.

Why this works

The single biggest liability risk in an AI-drafted privacy policy is a confidently asserted compliance claim — a model given a template-style prompt will often include boilerplate language like "we comply with GDPR and CCPA" because that phrase appears constantly in real privacy policies it learned from, without any actual verification that the described practices meet either framework's requirements, which is precisely the kind of assertion that turns a helpful draft into a legal exposure if it ships unreviewed; explicitly forbidding that specific claim, and requiring geography-dependent rights to be flagged rather than assumed, keeps the model from manufacturing false confidence in a document users will actually read and potentially rely on. Building the policy from the described data practices rather than a generic template matters because privacy policies are routinely scrutinized clause-by-clause against actual practice during a regulatory inquiry or a lawsuit, and boilerplate language describing data handling the company doesn't actually do (or omitting handling it does do) is worse than an incomplete but accurate policy — a template swap-in produces exactly that mismatch risk. Requiring missing information (like retention periods) to be flagged rather than filled with an invented plausible default addresses the model's tendency to complete a structured document fully even when a specific fact wasn't provided, which here would mean fabricating a retention period that the company doesn't actually follow, creating a policy that promises something operationally untrue. Keeping the invented-detail prohibition explicit for third-party vendor names and rights processes closes the same gap for the sections most likely to be wrong in exactly the way a regulator or a plaintiff's lawyer would find first.

What you get back

Data We Collect: We collect your name, email address, IP address, and in-app usage data when you use our product. Why: Email is used for account access and product updates; usage data helps us improve features. Sharing: We share payment information with Stripe and usage analytics with Mixpanel; we do not sell data to advertisers. Flagged for legal review: retention period not specified — needs input; EU user rights (GDPR) require specific confirmation of applicability and process, not assumed. This is a first draft, not a finished policy — a qualified privacy lawyer must review it against applicable regulations before publishing.

Verified against

ChatGPT GPT-5.1 · 2026-08-11

Changelog

  • 2026-08-11 Initial publish, verified against ChatGPT GPT-5.1.

Need this built into your business?

If a prompt isn't enough — what Scult builds, built and maintained for you — that's Scult's day job.

EXPLORE WHAT SCULT BUILDS
All Legal & Compliance prompts

Check your AI visibility

One URL in, a 0–100 score and the exact fixes out.

RUN THE CHECK

Browse all the tools

15 tools across six categories
13 of them never send your data anywhere

Free · No signup · No trial clock

SEE THE DIRECTORY