Generates comprehensive privacy policies by scanning websites for data collection signals including cookies, forms, payment processors, and third-party scripts.

MITAuto-check passedLegal & Compliance

Install Privacy Generator

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill privacy-generator -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace privacy-generator --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/privacy-generator .claude/skills/privacy-generator && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
privacy-generator
GitHub stars
2.8k
Token cost
~2.4k tokens
SKILL.md length
999 words
Files
1
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Generates comprehensive privacy policies by scanning websites for data collection signals including cookies, forms, payment processors, and third-party scripts.

  • Works in 10 steps: Scan for data collection signals. Use… → If scanning a codebase instead, use Glob… → Classify data types collected. Map… → …
  • Launching a website
  • SKILL.md covers Overview, Prerequisites, Instructions and Output, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Privacy Generator is an agent skill from jeremylongshore/tons-of-skills-marketplace. Generates comprehensive privacy policies by scanning websites for data collection signals including cookies, forms, payment processors, and third-party scripts. Use when launching a website or app that collects user data and needs GDPR/CCPA compliance. Trigger with "/privacy-generator" or "create a privacy policy for my website".

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Designed for Claude Code

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Launching a website
  • App that collects user data and needs GDPR/CCPA compliance
  • With /privacy-generator
  • Create a privacy policy for my website

Example prompts

  • “/privacy-generator”
  • “create a privacy policy for my website”
  • “Use the privacy-generator skill to generate comprehensive privacy policies by scanning websites for data collection signals including cookies…”
  • “/privacy-generator”

Requirements

  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Glob, Grep, WebFetch

Workflow steps

10 steps, taken from the first numbered list in SKILL.md.

  1. Scan for data collection signals. Use WebFetch on the target URL to detect
  2. If scanning a codebase instead, use Glob and Grep to find
  3. Classify data types collected. Map detected signals to data categories
  4. Determine legal bases (GDPR). For each data category, assign
  5. Generate the 12-section privacy policy
  6. Detail GDPR rights (Section 7). Include all seven with exercise instructions
  7. Detail CCPA rights (Section 8). Include all six
  8. Generate cookie consent banner text. Two versions
  9. Tag assumptions. Insert [VERIFY] for any data practice inferred from signals
  10. Write the output file using the naming convention below.

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Glob
    • Grep
    • WebFetch

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • example-app.com
    • oag.ca.gov
    • ftc.gov
    • eur-lex.europa.eu
    • nist.gov
    • commonpaper.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Privacy Generator loads about 2.4k tokens when it runs. Until then it costs about 87 tokens; SKILL.md has 999 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~87
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 999 words, ~2,438 tokens.

Download SKILL.mdSave it as .claude/skills/privacy-generator/SKILL.md (or your agent's skills folder).
name
privacy-generator
description
Generates comprehensive privacy policies by scanning websites for data collection signals including cookies, forms, payment processors, and third-party scripts. Use when launching a website or app that collects user data and needs GDPR/CCPA compliance. Trigger with "/privacy-generator" or "create a privacy policy for my website".
allowed-tools
Read, Write, Glob, Grep, WebFetch
compatibility
Designed for Claude Code
version
1.1.0
author
Intent Solutions <jeremy@intentsolutions.io>
license
MIT
tags
legal, privacy-policy, gdpr, ccpa, data-protection, cookies

Privacy Policy Generator

Overview

Scans a website or application codebase to detect data collection signals — cookies, web forms, payment processors, analytics scripts, social media embeds, and third-party trackers — then generates a tailored privacy policy with 12 sections. Includes specific GDPR rights (7 individual rights), CCPA rights (6 consumer rights), and cookie consent banner text in both minimal and full GDPR formats.

The detection phase maps every data touchpoint to its legal basis and disclosure requirement, ensuring the generated policy accurately reflects actual data practices rather than relying on generic boilerplate.

Legal Disclaimer: This skill generates template documents for informational and educational purposes only. Generated privacy policies are not a substitute for legal advice. Data protection requirements vary by jurisdiction, industry, and data type. All documents should be reviewed by a licensed attorney and/or data protection officer before publication. No attorney-client relationship is created by using this tool.

Prerequisites

  • A live website URL or local codebase to scan
  • Knowledge of the business entity name and jurisdiction
  • Understanding of what data is collected and why (the scan detects signals but cannot capture server-side-only processing)

Instructions

  1. Scan for data collection signals. Use WebFetch on the target URL to detect:

    Signal CategoryWhat to Look For
    CookiesSet-Cookie headers, cookie consent banners, tracking pixels
    AnalyticsGoogle Analytics, Mixpanel, Amplitude, Hotjar, Segment
    FormsContact forms, registration, login, newsletter signup
    PaymentsStripe, PayPal, Square, Braintree, payment form fields
    SocialFacebook Pixel, Twitter tags, LinkedIn Insight, social login
    AdvertisingGoogle Ads, Facebook Ads, retargeting pixels
    CDN/Third-PartyCloudflare, AWS CloudFront, Google Fonts, embedded iframes
    Chat/SupportIntercom, Zendesk, Drift, live chat widgets
  2. If scanning a codebase instead, use Glob and Grep to find:

    • Cookie-setting code (document.cookie, setCookie, cookies middleware)
    • Analytics initialization (gtag, analytics.track, mixpanel.init)
    • Form handlers and data submission endpoints
    • Payment SDK imports and configurations
    • User model/schema definitions showing stored fields
    • Environment variables referencing third-party API keys
  3. Classify data types collected. Map detected signals to data categories:

    • Identifiers (name, email, phone, address)
    • Financial (payment card, bank account, transaction history)
    • Technical (IP address, device info, browser fingerprint)
    • Behavioral (browsing history, click patterns, purchase history)
    • Content (user uploads, messages, reviews)
    • Sensitive (health, biometric, political — flag these for special handling)
  4. Determine legal bases (GDPR). For each data category, assign:

    • Consent — marketing emails, non-essential cookies, analytics
    • Contract — account data, payment processing, service delivery
    • Legitimate interest — security logs, fraud prevention, basic analytics
    • Legal obligation — tax records, regulatory reporting
  5. Generate the 12-section privacy policy:

    #SectionCovers
    1IntroductionWho the company is, what this policy covers
    2Information We CollectData types, collection methods, sources
    3How We Use Your InformationPurposes mapped to legal bases
    4Cookies & TrackingCookie types, duration, opt-out mechanisms
    5Information SharingThird parties, categories, purposes
    6Data RetentionHow long each data type is kept
    7Your Rights Under GDPR7 specific rights with exercise instructions
    8Your Rights Under CCPA6 specific rights with exercise instructions
    9Data SecurityTechnical and organizational measures
    10International TransfersCross-border data flow safeguards
    11Children's PrivacyAge restrictions, COPPA compliance
    12Contact & UpdatesDPO contact, policy change notification
  6. Detail GDPR rights (Section 7). Include all seven with exercise instructions:

    1. Right of Access (Article 15) — request a copy of personal data
    2. Right to Rectification (Article 16) — correct inaccurate data
    3. Right to Erasure (Article 17) — "right to be forgotten"
    4. Right to Restrict Processing (Article 18) — limit data use
    5. Right to Data Portability (Article 20) — receive data in machine-readable format
    6. Right to Object (Article 21) — object to processing based on legitimate interest
    7. Rights Related to Automated Decision-Making (Article 22) — opt out of profiling
  7. Detail CCPA rights (Section 8). Include all six:

    1. Right to Know — what personal information is collected
    2. Right to Delete — request deletion of personal information
    3. Right to Opt-Out — "Do Not Sell or Share My Personal Information"
    4. Right to Non-Discrimination — equal service regardless of rights exercised
    5. Right to Correct — correct inaccurate personal information
    6. Right to Limit Use of Sensitive Information — restrict sensitive data processing
  8. Generate cookie consent banner text. Two versions:

    • Minimal (US): Brief notice with link to full policy
    • Full GDPR: Granular consent with necessary/analytics/marketing toggles
  9. Tag assumptions. Insert [VERIFY] for any data practice inferred from signals but not confirmed by the user (e.g., [VERIFY: Google Analytics detected — confirm if IP anonymization is enabled]).

  10. Write the output file using the naming convention below.

Show full SKILL.md (265 more words)Show less

Output

Generate a single Markdown file named PRIVACY-POLICY-{company}-{YYYY-MM-DD}.md with:

# Privacy Policy
**{Company Name}**

**Last Updated:** {date}
**Effective Date:** {date}

---

## Data Collection Summary
| Data Type | Source | Legal Basis | Retention |
|-----------|--------|-------------|-----------|
{table of all detected data points}

---

## 1. Introduction
{formal legal text}

> **Plain English:** {simple explanation}

{... sections 2-12 ...}

---

## Cookie Consent Banner Text

### Minimal Version (US)
{banner text}

### Full GDPR Version
{banner text with granular consent options}

---

**[VERIFY] Tags Summary:**
{numbered list of assumptions}

**Detection Results:** {count} data signals detected across {count} categories
**Generated by:** Legal Assistant Plugin — Not a substitute for legal counsel.

Error Handling

ErrorCauseSolution
Website unreachableURL down or behind authenticationAsk for a description of data practices or codebase path
No data signals detectedStatic site with no trackingGenerate minimal policy covering server logs and hosting
Sensitive data detectedHealth, biometric, or financial dataFlag for enhanced protection; recommend DPO consultation
Multiple jurisdictionsGlobal audience detectedInclude both GDPR and CCPA sections, add [VERIFY] for others
Server-side processing invisibleCannot detect backend data flowsAsk user to describe server-side data collection
Third-party script unrecognizedUnknown tracking pixel or SDKList as "unidentified third-party service" with [VERIFY]

Examples

Example 1: SaaS with Analytics and Payments

Request: "Generate a privacy policy for https://example-app.com"

Result: PRIVACY-POLICY-ExampleApp-2026-04-02.md detecting:

  • Google Analytics 4 (behavioral data, IP address)
  • Stripe payment processing (financial data)
  • Intercom chat widget (identifiers, conversation content)
  • HubSpot forms (email, name, company)
  • 12-section policy with GDPR + CCPA rights
  • Cookie consent banner in both formats
  • 6 [VERIFY] tags for server-side assumptions

Example 2: Content Blog with Newsletter

Request: "Create privacy policy for my WordPress blog with Mailchimp newsletter"

Result: PRIVACY-POLICY-MyBlog-2026-04-02.md detecting:

  • WordPress cookies (session, comment author)
  • Mailchimp email collection (consent-based)
  • Google Fonts (IP address to Google servers)
  • Simplified policy focusing on minimal data collection
  • GDPR consent basis for newsletter subscription

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/.curated/privacy-generator of jeremylongshore/tons-of-skills-marketplace.

Open the folder on GitHubat commit cfae287

Compare with similar skills

Privacy Generator next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Privacy Generator compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Privacy Generator this skilljeremylongshore/tons-of-skills-marketplace2.8k—~2.4kAutomated safety check: PassMIT
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms587—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    587 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    946 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    150 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Questions about Privacy Generator

What does Privacy Generator do?

Generates comprehensive privacy policies by scanning websites for data collection signals including cookies, forms, payment processors, and third-party scripts. Privacy Generator is an agent skill from jeremylongshore/tons-of-skills-marketplace. Generates comprehensive privacy policies by scanning websites for data collection signals including cookies, forms, payment processors, and third-party scripts.

When should I use Privacy Generator?

Privacy Generator fits situations like: launching a website; app that collects user data and needs GDPR/CCPA compliance; with /privacy-generator; create a privacy policy for my website.

How do I install Privacy Generator in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill privacy-generator -a claude-code`. Or copy the skill folder (skills/.curated/privacy-generator in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/privacy-generator in your project. Claude Code loads it when a task matches its description.

How do I install Privacy Generator in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill privacy-generator -a codex`. Or copy the skill folder (skills/.curated/privacy-generator in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/privacy-generator in your project. Codex loads it when a task matches its description.

Can I use Privacy Generator in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill privacy-generator -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/privacy-generator, .gemini/skills/privacy-generator, .github/skills/privacy-generator and .opencode/skills/privacy-generator in your project.

What does Privacy Generator need to run?

SKILL.md names no scripts, command-line tools or credentials: Privacy Generator is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Write, Glob, Grep, WebFetch. Compatibility (from SKILL.md): Designed for Claude Code.

Does Privacy Generator access the network?

SKILL.md names 6 domains. As links in the text: example-app.com, oag.ca.gov, ftc.gov, eur-lex.europa.eu, nist.gov and commonpaper.com. This is read from the text; nothing was executed.

Is Privacy Generator safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Privacy Generator use?

Privacy Generator is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Privacy Generator use?

About 2.4k tokens (SKILL.md is roughly 9.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Privacy Generator?

Skills that share tags, products or a category with Privacy Generator: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Privacy Generator?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.