Agent skill

Privacy Policy

by phuryn in phuryn/pm-skills

Draft a detailed privacy policy covering data types, jurisdiction, GDPR and compliance considerations, and clauses needing legal review.

MITAuto-check passedLegal & Compliance

Install Privacy Policy

skills CLI
$ npx skills add phuryn/pm-skills --skill privacy-policy -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install phuryn/pm-skills privacy-policy --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/phuryn/pm-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/pm-toolkit/skills/privacy-policy .claude/skills/privacy-policy && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
privacy-policy
GitHub stars
27k
Token cost
~2.7k tokens
SKILL.md length
1,361 words
Files
1
Skills in repo
67
Repo updated
First seen
Licence
MIT

At a glance

Draft a detailed privacy policy covering data types, jurisdiction, GDPR and compliance considerations, and clauses needing legal review.

  • Works in 7 steps: Research (if URL provided) → Clarify Data Collection → Identify Applicable Laws → …
  • Creating a privacy policy
  • SKILL.md covers Purpose, Important Disclaimer, Input Arguments and Process, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Privacy Policy is an agent skill from phuryn/pm-skills. Draft a detailed privacy policy covering data types, jurisdiction, GDPR and compliance considerations, and clauses needing legal review. Use when creating a privacy policy, updating data protection documentation, or preparing for compliance.

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: PM Skills Marketplace: 100+ agentic skills, commands, and plugins — from discovery to strategy, execution, launch, and growth. The licence is MIT.

When your agent uses it

  • Creating a privacy policy
  • Updating data protection documentation
  • Preparing for compliance

Example prompts

  • “/privacy-policy”

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Research (if URL provided)
  2. Clarify Data Collection
  3. Identify Applicable Laws
  4. Structure the Privacy Policy
  5. Use Plain Language
  6. Highlight Areas Needing Legal Review
  7. Provide Context

What it can do on your machine

Read from SKILL.md and the folder at commit 6058e29. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Privacy Policy loads about 2.7k tokens when it runs. Until then it costs about 64 tokens; SKILL.md has 1,361 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~64
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from phuryn/pm-skills at commit 6058e29, republished under its MIT licence (© phuryn). 1,361 words, ~2,665 tokens.

Download SKILL.mdSave it as .claude/skills/privacy-policy/SKILL.md (or your agent's skills folder).
name
privacy-policy
description
Draft a detailed privacy policy covering data types, jurisdiction, GDPR and compliance considerations, and clauses needing legal review. Use when creating a privacy policy, updating data protection documentation, or preparing for compliance.

Privacy Policy Generator

You are an experienced data privacy and compliance specialist. Your role is to help draft comprehensive, clear, and compliant privacy policies for digital products and services.

Purpose

Draft a detailed privacy policy for a product or service. The policy covers data types handled, applicable jurisdiction, and clearly marks clauses that require legal review. Provide plain-language explanations to ensure accessibility and transparency.

Important Disclaimer

This is for informational purposes only and does not constitute legal advice. Always have a qualified attorney specializing in data privacy law review the final policy before publication. Privacy policies are legally binding documents that establish your company's responsibilities and users' rights; professional legal review is essential.

Input Arguments

  • $PRODUCT_NAME: Name of the product or service
  • $PRODUCT_URL: URL or description of the product (optional; will be researched if provided)
  • $COMPANY_NAME: Legal name of your company
  • $COMPANY_ADDRESS: Company headquarters or registered address
  • $CONTACT_EMAIL: Email for privacy inquiries (e.g., privacy@company.com)
  • $INFORMATION_TYPES: Types of data collected (e.g., "names, emails, usage behavior, location data, payment information, device identifiers")
  • $JURISDICTION: Applicable jurisdiction (e.g., "United States," "European Union (GDPR)," "California (CCPA)")

Process

Step 1: Research (if URL provided)

If $PRODUCT_URL is provided:

  • Visit the product website
  • Identify what data is collected (forms, tracking, login, payments)
  • Note any third-party integrations (analytics, payment processors, SDKs)
  • Understand the product's primary features and use cases
Step 2: Clarify Data Collection

Map out all data your product collects:

  • Direct collection: What users enter (name, email, preferences)
  • Automatic collection: What is tracked (IP address, usage behavior, device info, cookies)
  • Third-party data: What comes from partners, integrations, or service providers
  • Special categories: Does the product handle health data, financial data, children's data, biometric data?
Step 3: Identify Applicable Laws

Note which laws apply:

  • GDPR (EU users): Stricter; requires explicit consent, data subject rights, DPA
  • CCPA/CPRA (California): Consumer rights to access, delete, opt-out
  • Other US states: Laws like VIPA, TDPSA emerging
  • Industry-specific: HIPAA (health), GLBA (finance), FERPA (education)
  • Determine if your product serves international users
Step 4: Structure the Privacy Policy

Organize in standard sections (detailed below).

Step 5: Use Plain Language

Write clearly and accessibly. Avoid technical jargon. Define terms when first used. Help users understand what data you collect and why.

Mark sections with [⚠️ LEGAL REVIEW REQUIRED] where jurisdiction-specific language, specific data rights, or legal clauses are needed.

Step 7: Provide Context

Include notes explaining:

  • Why each section is important
  • What decisions the company must make
  • Compliance considerations

Privacy Policy Template Structure

Preamble

A brief introduction explaining:

  • What the policy covers
  • When it was last updated
  • How users can contact you with questions
Key Sections
1. Information We Collect

Categories of data:

  • Personal information (name, email, account info)
  • Usage data (pages viewed, features used, time spent)
  • Device information (type, OS, browser, IP address)
  • Location data (if applicable)
  • Payment information (handled securely, often by third parties)
  • Communications (if users contact support)
  • [⚠️ LEGAL REVIEW REQUIRED] Sensitive or special categories (health, biometric, etc.)
2. How We Collect Information

Methods:

  • Directly from users (forms, registration, preferences)
  • Automatically (cookies, analytics, device sensors)
  • From third parties (partners, service providers, data brokers)
3. How We Use Information

Purposes (be specific, not vague):

  • Providing the service and customer support
  • Improving and personalizing the product
  • Analytics and understanding user behavior
  • Marketing and promotional communications
  • Security and fraud prevention
  • Legal compliance
  • [⚠️ LEGAL REVIEW REQUIRED] Other purposes (must be explicitly stated if you plan to use data for new purposes later)

[⚠️ LEGAL REVIEW REQUIRED] Especially important for GDPR:

  • Consent: User has explicitly agreed
  • Contract: Data is needed to provide the service
  • Legal obligation: Law requires processing
  • Vital interests: Protection of life or health
  • Public task: Part of your official function
  • Legitimate interests: Company has a legitimate business need
5. Data Sharing and Third Parties

Who has access to data:

  • Service providers (hosting, analytics, email, payments)
  • Business partners (if applicable)
  • Legal authorities (if required by law)
  • [⚠️ LEGAL REVIEW REQUIRED] Where third parties are located (especially if outside user's jurisdiction)
6. International Data Transfer

[⚠️ LEGAL REVIEW REQUIRED] If applicable:

  • How data is transferred across borders
  • Mechanisms used (Standard Contractual Clauses, adequacy decisions, user consent)
  • Where data is stored and processed
7. Data Retention

How long you keep data:

  • Account data: As long as account is active, then X months/years
  • Usage logs: X months
  • Deleted content: Y days before permanent deletion
  • [⚠️ LEGAL REVIEW REQUIRED] Be specific, not vague; many regulations require this
8. User Rights

[⚠️ LEGAL REVIEW REQUIRED] Varies by jurisdiction:

  • Right to access: Users can request copy of their data
  • Right to deletion: Users can request data be deleted ("right to be forgotten")
  • Right to correct: Users can update inaccurate data
  • Right to restrict processing: Users can limit how data is used
  • Right to data portability: Users can download their data
  • Right to opt-out: Users can unsubscribe from marketing
  • Right to lodge complaints: Users can contact data protection authorities
  • How users exercise these rights (contact info, process)
Show full SKILL.md (541 more words)Show less
9. Cookies and Tracking

[⚠️ LEGAL REVIEW REQUIRED] Detailed info:

  • What cookies and tracking tools are used
  • Why each is used (functionality, analytics, marketing)
  • How to manage/disable cookies
  • Whether explicit consent is required (GDPR requires it for non-essential cookies)
10. Security

Measures taken to protect data:

  • Encryption in transit and at rest
  • Access controls and authentication
  • Regular security audits
  • Incident response procedures
  • Limitations (no system is 100% secure)
11. Children's Privacy

[⚠️ LEGAL REVIEW REQUIRED] If product serves users under 13:

  • Parental consent mechanisms
  • Age gates or verification
  • Compliance with COPPA (US), UK Children's Code, similar laws
12. Contact and Rights

How users contact you:

  • Privacy contact email
  • Mailing address
  • Response timeframe for requests
  • Data Protection Officer (if required)
13. Policy Changes

How you'll communicate changes:

  • Notice period (e.g., 30 days)
  • How you'll notify (email, in-app, website)
  • User's ability to opt-out if changes are material
14. Additional Provisions
  • No sale of data: Whether you sell/share data (if not, explicitly state)
  • Third-party links: You're not responsible for external sites
  • Governing law: Which jurisdiction's laws govern
  • Effective date: When policy became active

Content Guidelines

  • Be specific: Don't say "we use your data for product improvement"; say "we analyze usage patterns to identify features that users find confusing and prioritize improvements to those features"
  • Plain language: Write for a general audience, not lawyers. Explain what data you collect and why in simple terms
  • Transparency: Be honest about all data collection, including analytics, third parties, and uses
  • User control: Explain how users can access, delete, or opt-out of data processing
  • Align with practice: The policy must match what your product actually does; if it doesn't, change the product or the policy
  • Complete information types: Use $INFORMATION_TYPES to make the policy specific to your actual data collection

Output Format

Present the privacy policy in three parts:

Part 1: Summary

Quick reference:

  • Product name and purpose
  • Data types collected
  • Jurisdiction(s) covered
  • Key user rights
  • Retention periods
  • Contact information
Part 2: Full Privacy Policy Document

A complete, ready-to-publish privacy policy.

Part 3: Customization and Compliance Notes

Guidance on:

  • Sections marked for legal review
  • Jurisdiction-specific considerations (GDPR, CCPA, etc.)
  • Compliance checklist
  • Common modifications based on product type
  • Next steps (legal review, implementation, user communication)

Key Compliance Reminders

  • GDPR compliance (if serving EU users): Requires explicit consent, clear rights, DPA with processors, DPIA for risky processing
  • CCPA/CPRA (California users): Requires rights to access, delete, opt-out; detailed disclosures; no discrimination for exercising rights
  • Transparency: Users must understand what data is collected, how it's used, and who can access it
  • Accuracy: Keep your policy updated as data practices change
  • Enforcement: Privacy violations can result in fines, user lawsuits, and reputational damage
  • Get legal review: Before publishing, have a data privacy attorney in your jurisdiction review the policy

Before You Publish

  • Have a data privacy attorney review the policy
  • Ensure the policy matches your actual data collection and use
  • Make privacy request processes easy for users (accessible contact info, quick response)
  • Implement technical measures mentioned in the policy (encryption, access controls, etc.)
  • Set up systems to handle data subject rights requests (access, deletion, etc.)
  • Document your legal basis for each type of processing
  • Have a Data Processing Agreement (DPA) with all third-party processors
  • Notify users of material changes; consider giving them a choice to opt-out

© phuryn, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in pm-toolkit/skills/privacy-policy of phuryn/pm-skills.

Open the folder on GitHubat commit 6058e29

Compare with similar skills

Privacy Policy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Privacy Policy compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Privacy Policy this skillphuryn/pm-skills27k—~2.7kAutomated safety check: PassMIT
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms587—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    587 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    946 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    150 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes

More from phuryn/pm-skills

All 67 skills in this repo
  • Reviews a diff by anchoring on agreements between two sides of a boundary, forcing a concrete violating execution, and refuting each finding before reporting it.

    27k GitHub stars~3.6k tokensUpdated yesterday
    Auto-check passed
  • A/B Test Analysis

    phuryn/pm-skills

    Validates an experiment's setup, works out lift, p-value and confidence interval from A/B test data, and recommends whether to ship, extend or stop.

    27k GitHub stars~893 tokensUpdated yesterday
    Auto-check passed
  • Team OKR Brainstorm

    phuryn/pm-skills

    Drafts three alternative sets of team OKRs, each with an inspiring objective and measurable key results, tied to the company strategy you provide.

    27k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Analyzes uploaded cohort data to compute retention curves and feature adoption trends, builds heatmaps and charts, and suggests qualitative follow-up research.

    27k GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Dummy Dataset Generator

    phuryn/pm-skills

    Generates realistic test datasets with custom columns, row counts and business constraints, output as CSV, JSON, SQL inserts or a runnable Python script.

    27k GitHub stars~983 tokensUpdated yesterday
    Auto-check passed
  • Grammar and Flow Checker

    phuryn/pm-skills

    Reviews a draft for grammar, logic and flow problems and returns located, prioritized fix suggestions without rewriting the whole text.

    27k GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed

Questions about Privacy Policy

What does Privacy Policy do?

Draft a detailed privacy policy covering data types, jurisdiction, GDPR and compliance considerations, and clauses needing legal review. Privacy Policy is an agent skill from phuryn/pm-skills. Draft a detailed privacy policy covering data types, jurisdiction, GDPR and compliance considerations, and clauses needing legal review.

When should I use Privacy Policy?

Privacy Policy fits situations like: creating a privacy policy; updating data protection documentation; preparing for compliance.

How do I install Privacy Policy in Claude Code?

Run `npx skills add phuryn/pm-skills --skill privacy-policy -a claude-code`. Or copy the skill folder (pm-toolkit/skills/privacy-policy in phuryn/pm-skills) into .claude/skills/privacy-policy in your project. Claude Code loads it when a task matches its description.

How do I install Privacy Policy in Codex?

Run `npx skills add phuryn/pm-skills --skill privacy-policy -a codex`. Or copy the skill folder (pm-toolkit/skills/privacy-policy in phuryn/pm-skills) into .agents/skills/privacy-policy in your project. Codex loads it when a task matches its description.

Can I use Privacy Policy in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add phuryn/pm-skills --skill privacy-policy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/privacy-policy, .gemini/skills/privacy-policy, .github/skills/privacy-policy and .opencode/skills/privacy-policy in your project.

What does Privacy Policy need to run?

SKILL.md names no scripts, command-line tools or credentials: Privacy Policy is instructions for the agent only.

Does Privacy Policy access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Privacy Policy safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Privacy Policy use?

Privacy Policy is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Privacy Policy use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Privacy Policy?

Skills that share tags, products or a category with Privacy Policy: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Privacy Policy?

phuryn (a GitHub user) maintains it in phuryn/pm-skills, which has 26,862 GitHub stars. The repository holds 67 skills in this directory. The repository was last updated on October 9, 2026.

Source: phuryn/pm-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.