Agent skill

Privacy Policy

by shawnpang in shawnpang/startup-founder-skills

When the user needs to draft, review, or update a privacy policy for their product, or needs to understand data privacy obligations across jurisdictions.

MITAuto-check passedLegal & Compliance

Install Privacy Policy

skills CLI
$ npx skills add shawnpang/startup-founder-skills --skill privacy-policy -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install shawnpang/startup-founder-skills privacy-policy --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/shawnpang/startup-founder-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy-policy .claude/skills/privacy-policy && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
privacy-policy
GitHub stars
343
Token cost
~2.2k tokens
SKILL.md length
1,089 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

When the user needs to draft, review, or update a privacy policy for their product, or needs to understand data privacy obligations across jurisdictions.

  • Works in 7 steps: Research the product -- Visit the… → Map data collection -- Categorize all… → Identify applicable laws -- Based on… → …
  • Update a privacy policy for their product
  • SKILL.md covers When to Use, Context Required, Workflow and Output Format, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Privacy Policy is an agent skill from shawnpang/startup-founder-skills. When the user needs to draft, review, or update a privacy policy for their product, or needs to understand data privacy obligations across jurisdictions.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: AI agent skills for tech startup founders — fundraising, sales, product, recruiting, engineering, legal, ops, and growth. Works with Claude Code, Cursor, Codex, and any Agent… The licence is MIT.

When your agent uses it

  • Update a privacy policy for their product
  • Needs to understand data privacy obligations across jurisdictions

Example prompts

  • “/privacy-policy”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Research the product -- Visit the product website or review the product description. Identify all data collection methods, third-party…
  2. Map data collection -- Categorize all data into: directly provided (forms, account creation), automatically collected (cookies, device…
  3. Identify applicable laws -- Based on where users are located and where the company operates, determine which privacy frameworks apply…
  4. Structure the policy -- Organize using the 15-section template below. Write in plain language at an 8th-grade reading level. Be specific…
  5. Flag legal review areas -- Mark sections requiring attorney review with [LEGAL REVIEW REQUIRED] notation. These include legal basis…
  6. Provide implementation context -- Explain why each section matters, what company decisions are needed, and what compliance considerations…
  7. Generate compliance summary -- Produce a separate document with data inventory table, jurisdiction applicability matrix, risk flags, and…

What it can do on your machine

Read from SKILL.md and the folder at commit 4ad31b4. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Privacy Policy loads about 2.2k tokens when it runs. Until then it costs about 42 tokens; SKILL.md has 1,089 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~42
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from shawnpang/startup-founder-skills at commit 4ad31b4, republished under its MIT licence (© shawnpang). 1,089 words, ~2,189 tokens.

Download SKILL.mdSave it as .claude/skills/privacy-policy/SKILL.md (or your agent's skills folder).
name
privacy-policy
description
When the user needs to draft, review, or update a privacy policy for their product, or needs to understand data privacy obligations across jurisdictions.
related
terms-of-service, soc2-prep
reads
startup-context

Privacy Policy

When to Use

Activate when a founder needs to create a privacy policy for a new product launch, update an existing policy for new data practices or features, expand into a new jurisdiction (EU, California, etc.), or assess whether current data handling is properly disclosed. Also activate when the user asks about GDPR, CCPA, CPRA, or general data privacy compliance.

Context Required

  • From startup-context: product type, platform (web/mobile/API), target customer segments, geographic markets, business model, tech stack.
  • From the user: product name and URL, company legal name and address, contact email for privacy inquiries, what personal data is collected and how, which third-party services process data (analytics, payment processors, CRMs, AI providers), applicable jurisdictions, whether the product targets minors, and any existing privacy documentation.

Workflow

  1. Research the product -- Visit the product website or review the product description. Identify all data collection methods, third-party integrations, and primary features that involve personal data.
  2. Map data collection -- Categorize all data into: directly provided (forms, account creation), automatically collected (cookies, device info, usage data, IP addresses), third-party sources, and special/sensitive categories. Build a structured data inventory.
  3. Identify applicable laws -- Based on where users are located and where the company operates, determine which privacy frameworks apply: GDPR, CCPA/CPRA, state privacy laws, COPPA, industry-specific regulations. Note specific obligations per jurisdiction.
  4. Structure the policy -- Organize using the 15-section template below. Write in plain language at an 8th-grade reading level. Be specific about actual practices -- say "We collect your email address when you sign up" rather than "We may process identifiers."
  5. Flag legal review areas -- Mark sections requiring attorney review with [LEGAL REVIEW REQUIRED] notation. These include legal basis determinations, international transfer mechanisms, and jurisdiction-specific rights.
  6. Provide implementation context -- Explain why each section matters, what company decisions are needed, and what compliance considerations apply. Include a pre-publication checklist.
  7. Generate compliance summary -- Produce a separate document with data inventory table, jurisdiction applicability matrix, risk flags, and implementation checklist.

Output Format

Three-part deliverable:

Part 1: Quick Reference Summary

Product details, data types collected, applicable jurisdictions, user rights summary, retention overview, and contact information.

Part 2: Full Policy Document (15 sections)
  1. Preamble -- Who you are, what this policy covers, effective date, contact methods.
  2. Information We Collect -- Categories: personal info, usage data, device information, location, payment info, communications, sensitive data.
  3. How We Collect Information -- Methods: direct entry, automatic tracking, third parties.
  4. How We Use Information -- Purposes: service provision, support, improvements, analytics, marketing, security, legal compliance.
  5. Legal Basis for Processing -- Consent, contract performance, legal obligation, vital interests, legitimate interests (GDPR-focused).
  6. Data Sharing and Third Parties -- Service providers, partners, legal authorities, with specifics on who and why.
  7. International Data Transfer -- Cross-border transfer mechanisms (SCCs, adequacy decisions), storage locations.
  8. Data Retention -- Specific timeframes for account data, logs, deleted content.
  9. User Rights -- Access, deletion, correction, restrict processing, portability, opt-out, complaint procedures -- organized by jurisdiction.
  10. Cookies and Tracking -- Tools used, purposes, management options, consent requirements.
  11. Security -- Encryption, access controls, audits, incident response, limitations.
  12. Children's Privacy -- Parental consent, age gates, COPPA/UK Children's Code compliance.
  13. Contact and Rights Requests -- Privacy email, address, response timeframes, DPO info.
  14. Policy Changes -- Notice period, notification methods, user opt-out options.
  15. Additional Provisions -- Data sale disclosure, third-party link disclaimers, governing law, effective date.
Part 3: Compliance Notes
  • Sections flagged for legal review with rationale
  • Jurisdiction-specific considerations
  • Pre-publication checklist (see below)
  • Recommended modifications by product type

Frameworks & Best Practices

GDPR Core Requirements
  • Lawful basis required for each processing activity (Art. 6).
  • Data Protection Impact Assessment for high-risk processing (Art. 35).
  • 72-hour breach notification to supervisory authority (Art. 33).
  • Data Processing Agreements with all processors (Art. 28).
  • Right to erasure with defined exceptions (Art. 17).
  • Privacy by design and by default (Art. 25).
Show full SKILL.md (459 more words)Show less
CCPA/CPRA Core Requirements
  • "Do Not Sell or Share My Personal Information" link required if applicable.
  • Right to know, delete, correct, and opt out of sale/sharing.
  • 12-month lookback for data collection disclosures.
  • Sensitive personal information: right to limit use (CPRA addition).
  • Service provider vs. contractor vs. third party distinctions matter.
Plain Language Principles
  • Write at an 8th-grade reading level with short sentences.
  • Use concrete examples instead of abstract categories.
  • Avoid "may" when you mean "do." Be specific about actual practices.
  • The policy must match what your product actually does -- no over-disclosure and no under-disclosure.
Pre-Publication Checklist
  • Attorney review completed
  • Policy matches actual data practices
  • User privacy request processes are accessible and functional
  • Technical security measures implemented
  • Data Processing Agreements in place with all third parties
  • Legal basis documented for each processing activity
  • Cookie consent mechanism implemented (EU users)
  • User notification system for material policy changes
Common Startup Pitfalls
  • Copying another company's privacy policy (their data practices are not yours).
  • Missing analytics and advertising SDKs in disclosures (Google Analytics, Mixpanel, Facebook Pixel all collect personal data).
  • No mechanism to actually fulfill deletion requests in the codebase.
  • Assuming B2B means no privacy obligations (you still process individual user data).
  • Listing data categories you do not actually collect (over-disclosure invites scrutiny).
  • terms-of-service -- Draft alongside the privacy policy; they should cross-reference each other and use consistent definitions.
  • soc2-prep -- SOC 2 Trust Service Criteria for Privacy directly overlaps with privacy policy commitments.
  • security-review -- Security measures described in the privacy policy must reflect actual technical controls.

Examples

Example 1: New SaaS product launching in US and EU

User: "We're launching our project management SaaS next month with users from the US and Europe. We use Stripe, Mixpanel, and AWS."

Good output: A three-part deliverable. The data inventory table mapping each data category to collection method, purpose, legal basis, third parties, and retention. Jurisdiction analysis identifying GDPR applicability and CCPA threshold monitoring. Red flags for Mixpanel IP collection needing disclosure and DPA, and missing cookie consent mechanism for EU users.

Example 2: Updating policy after adding AI features

User: "We added an AI assistant that processes customer messages. Do we need to update our privacy policy?"

Good output: Identifies the new data processing (message content processed by AI models), new third party (AI provider as sub-processor), new legal basis analysis needed, and GDPR Art. 22 consideration for automated decision-making. Provides the specific policy sections that need updating with draft language.


Disclaimer: This skill generates draft privacy policies and compliance guidance for educational and planning purposes only. It does not constitute legal advice. Always have a qualified attorney licensed in your relevant jurisdictions review the final privacy policy before publication. Regulatory non-compliance can result in significant fines (up to 4% of global annual revenue under GDPR).

© shawnpang, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/privacy-policy of shawnpang/startup-founder-skills.

Open the folder on GitHubat commit 4ad31b4

Compare with similar skills

Privacy Policy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Privacy Policy compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Privacy Policy this skillshawnpang/startup-founder-skills343—~2.2kAutomated safety check: PassMIT
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms587—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    587 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    946 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    150 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes

More from shawnpang/startup-founder-skills

All 50 skills in this repo
  • Accelerator Application

    shawnpang/startup-founder-skills

    When the user wants to apply to startup accelerators, incubators, or fellowship programs.

    343 GitHub stars~2.7k tokensUpdated 6 mo ago
    Auto-check passed
  • Architecture Design

    shawnpang/startup-founder-skills

    When the user needs to design or evaluate system architecture — service boundaries, data models, API contracts, infrastructure topology, database selection, or dependency analysis.

    343 GitHub stars~2.1k tokensUpdated 6 mo ago
    Auto-check passed
  • Board Update

    shawnpang/startup-founder-skills

    When the user needs to write a monthly or quarterly investor update, prepare a board deck, or communicate company progress to stakeholders.

    343 GitHub stars~2.3k tokensUpdated 6 mo ago
    Auto-check passed
  • Churn Analysis

    shawnpang/startup-founder-skills

    When the user needs to identify at-risk accounts, understand why customers are leaving, reduce churn rate, build health scores, design save plays, or create win-back campaigns.

    343 GitHub stars~2.3k tokensUpdated 6 mo ago
    Auto-check passed
  • Cicd Setup

    shawnpang/startup-founder-skills

    When the user needs to set up or improve CI/CD pipelines — GitHub Actions, GitLab CI, deployment automation, or says "set up CI", "automate deployment", "add tests to pipeline", "fix my build".

    343 GitHub stars~1.7k tokensUpdated 6 mo ago
    Auto-check passed
  • Code Review

    shawnpang/startup-founder-skills

    When the user asks for a code review, shares code for feedback, or says "review this", "check my code", "what's wrong with this".

    343 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed

Questions about Privacy Policy

What does Privacy Policy do?

When the user needs to draft, review, or update a privacy policy for their product, or needs to understand data privacy obligations across jurisdictions. Privacy Policy is an agent skill from shawnpang/startup-founder-skills. When the user needs to draft, review, or update a privacy policy for their product, or needs to understand data privacy obligations across jurisdictions.

When should I use Privacy Policy?

Privacy Policy fits situations like: update a privacy policy for their product; needs to understand data privacy obligations across jurisdictions.

How do I install Privacy Policy in Claude Code?

Run `npx skills add shawnpang/startup-founder-skills --skill privacy-policy -a claude-code`. Or copy the skill folder (skills/privacy-policy in shawnpang/startup-founder-skills) into .claude/skills/privacy-policy in your project. Claude Code loads it when a task matches its description.

How do I install Privacy Policy in Codex?

Run `npx skills add shawnpang/startup-founder-skills --skill privacy-policy -a codex`. Or copy the skill folder (skills/privacy-policy in shawnpang/startup-founder-skills) into .agents/skills/privacy-policy in your project. Codex loads it when a task matches its description.

Can I use Privacy Policy in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add shawnpang/startup-founder-skills --skill privacy-policy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/privacy-policy, .gemini/skills/privacy-policy, .github/skills/privacy-policy and .opencode/skills/privacy-policy in your project.

What does Privacy Policy need to run?

SKILL.md names no scripts, command-line tools or credentials: Privacy Policy is instructions for the agent only.

Does Privacy Policy access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Privacy Policy safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Privacy Policy use?

Privacy Policy is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Privacy Policy use?

About 2.2k tokens (SKILL.md is roughly 8.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Privacy Policy?

Skills that share tags, products or a category with Privacy Policy: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Privacy Policy?

shawnpang (a GitHub user) maintains it in shawnpang/startup-founder-skills, which has 343 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on March 16, 2026.

Source: shawnpang/startup-founder-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.