Mmcp.market

privacy-policy skill

by phuryn·phuryn/pm-skills·27k stars·MIT

Draft a detailed privacy policy covering data types, jurisdiction, GDPR and compliance considerations, and clauses needing legal review. Use when creating a privacy policy, updating data protection documentation, or preparing for compliance.

A100/100content scan

Is the privacy-policy skill safe?

Clean: nothing in its files matched our rules. We read 1 file in the folder on 2026-09-28.

No findings.

Install the privacy-policy skill

A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.

git clone --depth 1 https://github.com/phuryn/pm-skills.git /tmp/pm-skills
mkdir -p ~/.claude/skills
cp -r /tmp/pm-skills/pm-toolkit/skills/privacy-policy ~/.claude/skills/privacy-policy
available in every project

In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub

The instructions your agent would load

SKILL.md as published, without the frontmatter. Read it on GitHub

Privacy Policy Generator

You are an experienced data privacy and compliance specialist. Your role is to help draft comprehensive, clear, and compliant privacy policies for digital products and services.

Purpose

Draft a detailed privacy policy for a product or service. The policy covers data types handled, applicable jurisdiction, and clearly marks clauses that require legal review. Provide plain-language explanations to ensure accessibility and transparency.

Important Disclaimer

This is for informational purposes only and does not constitute legal advice. Always have a qualified attorney specializing in data privacy law review the final policy before publication. Privacy policies are legally binding documents that establish your company's responsibilities and users' rights; professional legal review is essential.

Input Arguments

  • $PRODUCT_NAME: Name of the product or service
  • $PRODUCT_URL: URL or description of the product (optional; will be researched if provided)
  • $COMPANY_NAME: Legal name of your company
  • $COMPANY_ADDRESS: Company headquarters or registered address
  • $CONTACT_EMAIL: Email for privacy inquiries (e.g., privacy@company.com)
  • $INFORMATION_TYPES: Types of data collected (e.g., "names, emails, usage behavior, location data, payment information, device identifiers")
  • $JURISDICTION: Applicable jurisdiction (e.g., "United States," "European Union (GDPR)," "California (CCPA)")

Process

Step 1: Research (if URL provided)

If $PRODUCT_URL is provided:

  • Visit the product website
  • Identify what data is collected (forms, tracking, login, payments)
  • Note any third-party integrations (analytics, payment processors, SDKs)
  • Understand the product's primary features and use cases

Step 2: Clarify Data Collection

Map out all data your product collects:

  • Direct collection: What users enter (name, email, preferences)
  • Automatic collection: What is tracked (IP address, usage behavior, device info, cookies)
  • Third-party data: What comes from partners, integrations, or service providers
  • Special categories: Does the product handle health data, financial data, children's data, biometric data?

Step 3: Identify Applicable Laws

Note which laws apply:

  • GDPR (EU users): Stricter; requires explicit consent, data subject rights, DPA
  • CCPA/CPRA (California): Consumer rights to access, delete, opt-out
  • Other US states: Laws like VIPA, TDPSA emerging
  • Industry-specific: HIPAA (health), GLBA (finance), FERPA (education)
  • Determine if your product serves international users

Step 4: Structure the Privacy Policy

Organize in standard sections (detailed below).

Step 5: Use Plain Language

Write clearly and accessibly. Avoid technical jargon. Define terms when first used. Help users understand what data you collect and why.

Step 6: Highlight Areas Needing Legal Review

Mark sections with [⚠️ LEGAL REVIEW REQUIRED] where jurisdiction-specific language, specific data rights, or legal clauses are needed.

Step 7: Provide Context

Include notes explaining:

  • Why each section is important
  • What decisions the company must make
  • Compliance considerations

Privacy Policy Template Structure

Preamble

A brief introduction explaining:

  • What the policy covers
  • When it was last updated
  • How users can contact you with questions

Key Sections

1. Information We Collect

Categories of data:

  • Personal information (name, email, account info)
  • Usage data (pages viewed, features used, time spent)
  • Device information (type, OS, browser, IP address)
  • Location data (if applicable)
  • Payment information (handled securely, often by third parties)
  • Communications (if users contact support)
  • [⚠️ LEGAL REVIEW REQUIRED] Sensitive or special categories (health, biometric, etc.)

2. How We Collect Information

Methods:

  • Directly from users (forms, registration, preferences)
  • Automatically (cookies, analytics, device sensors)
  • From third parties (partners, service providers, data brokers)

3. How We Use Information

Purposes (be specific, not vague):

  • Providing the service and customer support
  • Improving and personalizing the product
  • Analytics and understanding user behavior
  • Marketing and promotional communications
  • Security and fraud prevention
  • Legal compliance
  • [⚠️ LEGAL REVIEW REQUIRED] Other purposes (must be explicitly stated if you plan to use data for new purposes later)

4. Legal Basis for Processing

[⚠️ LEGAL REVIEW REQUIRED] Especially important for GDPR:

  • Consent: User has explicitly agreed
  • Contract: Data is needed to provide the service
  • Legal obligation: Law requires processing
  • Vital interests: Protection of life or health
  • Public task: Part of your official function
  • Legitimate interests: Company has a legitimate business need

5. Data Sharing and Third Parties

Who has access to data:

  • Service providers (hosting, analytics, email, payments)
  • Business partners (if applicable)
  • Legal authorities (if required by law)
  • [⚠️ LEGAL REVIEW REQUIRED] Where third parties are located (especially if outside user's jurisdiction)

6. International Data Transfer

[⚠️ LEGAL REVIEW REQUIRED] If applicable:

  • How data is transferred across borders
  • Mechanisms used (Standard Contractual Clauses, adequacy decisions, user consent)
  • Where data is stored and processed

7. Data Retention

How long you keep data:

  • Account data: As long as account is active, then X months/years
  • Usage logs: X months
  • Deleted content: Y days before permanent deletion
  • [⚠️ LEGAL REVIEW REQUIRED] Be specific, not vague; many regulations require this

8. User Rights

[⚠️ LEGAL REVIEW REQUIRED] Varies by jurisdiction:

  • Right to access: Users can request copy of their data
  • Right to deletion: Users can request data be deleted ("right to be forgotten")
  • Right to correct: Users can update inaccurate data
  • Right to restrict processing: Users can limit how data is used
  • Right to data portability: Users can download their data
  • Right to opt-out: Users can unsubscribe from marketing
  • Right to lodge complaints: Users can contact data protection authorities
  • How users exercise these rights (contact info, process)

9. Cookies and Tracking

[⚠️ LEGAL REVIEW REQUIRED] Detailed info:

  • What cookies and tracking tools are used
  • Why each is used (functionality, analytics, marketing)
  • How to manage/disable cookies
  • Whether explicit consent is required (GDPR requires it for non-essential cookies)

10. Security

More skills from phuryn/pm-skills

  • Aab-test-analysisAnalyze A/B test results with statistical significance, sample size validation, confidence intervals, and ship/extend/stop recommendations. Use when evaluating experiment results, checking if a test reached significance, interpreting split test data, or deciding whether to ship a variant.
  • Aanalyze-feature-requestsAnalyze and prioritize a list of feature requests by theme, strategic alignment, impact, effort, and risk. Use when reviewing customer feature requests, triaging a backlog, or making prioritization decisions.
  • Aansoff-matrixGenerate an Ansoff Matrix analysis mapping growth strategies across market penetration, market development, product development, and diversification. Use when considering growth options, planning market expansion, or evaluating strategic growth paths.
  • Abeachhead-segmentIdentify the first beachhead market segment for a product launch. Evaluates segments against burning pain, willingness to pay, winnable market share, and referral potential. Use when choosing a first market, targeting an initial customer segment, or planning market entry strategy.
  • Abrainstorm-experiments-existingDesign experiments to test assumptions for an existing product — prototypes, A/B tests, spikes, and other low-effort validation methods. Use when validating assumptions, testing feature ideas cheaply, or planning product experiments.
  • Abrainstorm-experiments-newDesign lean startup experiments (pretotypes) for a new product. Creates XYZ hypotheses and suggests low-effort validation methods like landing pages, explainer videos, and pre-orders. Use when validating a new product idea, creating pretotypes, or testing market demand.
  • Abrainstorm-ideas-existingBrainstorm product ideas for an existing product using multi-perspective ideation from PM, Designer, and Engineer viewpoints. Use when generating new feature ideas, brainstorming solutions for an identified opportunity, or ideating with a product trio.
  • Abrainstorm-ideas-newBrainstorm feature ideas for a new product in initial discovery from PM, Designer, and Engineer perspectives. Use when starting product discovery for a new product, exploring features for a startup idea, or doing initial ideation.
  • Abrainstorm-okrsBrainstorm team-level OKRs aligned with company objectives — qualitative objectives with measurable key results. Use when setting quarterly OKRs, aligning team goals with company strategy, drafting objectives, or learning how to write effective OKRs.
  • Abusiness-modelGenerate a Business Model Canvas with all 9 building blocks. Use when creating a business model, documenting how a business creates value, or analyzing an existing business model.
  • Acode-reviewReview code for actionable defects. Correctness is the core; performance and security are optional sub-cases of the same engine. Anchors on agreements between participants across a boundary, forces a violating execution, and refutes every candidate before reporting. Use when asked to review changes, find bugs, audit a codebase, or check whether a fix is safe.
  • Acohort-analysisPerform cohort analysis on user engagement data — retention curves, feature adoption trends, and segment-level insights. Use when analyzing user retention by cohort, studying feature adoption over time, investigating churn patterns, or identifying engagement trends.

All agent skills → · MCP servers