Oxwyn Studio

Free tool

Build a privacy policy for your website

This free tool builds a starter privacy and cookie policy for your website. Answer a short set of questions about what data you collect and why, and it assembles a plain-English draft you can copy, edit and publish. Everything runs in your browser. Nothing you type is sent to us or stored anywhere.

What personal data do you collect
Which tools or services you use

Your starter privacy and cookie policy

Privacy Policy
Effective date: 30 August 2026

Your Business ("we", "us") operates www.yourwebsite.co.uk. This policy explains what personal data we collect, why we collect it, who we share it with, and the choices you have.

Data we collect
- Name
- Email

Why we collect it
We use the details above to respond to your enquiries, to provide the services you ask for, and to understand how visitors use our site so we can improve it. We only collect what we need for these purposes.

Sharing your data
We do not sell your personal data. We share it only with the service providers listed above, and only so far as they need it to work for us, or where the law requires us to.

Cookies
Our site uses essential cookies so it can function, and it may set analytics and marketing cookies through the tools listed above. You can control or clear cookies through your browser settings, and where required we ask for your consent before setting non-essential cookies.

Your choices
You can ask us to access, correct or delete the personal data we hold about you, and to object to certain uses of it. Depending on where you live you may have further rights under your local privacy law. Contact us at hello@yourwebsite.co.uk and we will respond.

Changes to this policy
We update this policy when the way we handle data changes. The effective date at the top shows when it last changed.

Contact
For any privacy question or request, email us at hello@yourwebsite.co.uk.

[This is a starter template. Have it reviewed by a solicitor or attorney before you publish.]

This is a starting template, not legal advice, and not a guarantee of compliance with UK GDPR, CCPA or any US state law. It cannot know which laws apply to you. Read every line, edit it to match how your business really works, and if you handle sensitive, children's, health or financial data, or you sell data, have a solicitor or attorney review it before you publish.

Runs in your browser. Nothing you type is sent to us or stored anywhere.

This is a starting template, not legal advice

This tool produces a starter template to work from. It is not legal advice, not a substitute for a solicitor or attorney, and not a guarantee of compliance with UK GDPR, the California CCPA/CPRA, or any other US state privacy law. As of 2026 around twenty US states have their own comprehensive privacy laws already in force, with more enacted and coming, and each sets different rules on thresholds, sensitive data, opt-outs and penalties. Those laws also change. This generator cannot know which apply to you or cover them all. If you handle sensitive data, children's data, health or financial information, or you sell or share personal data, have a qualified solicitor or attorney review your policy before you publish. Treat the output as a first draft that a human still needs to check.

Why your website needs a privacy policy

If your site collects any personal data, a contact form, an email signup, analytics or cookies, most people expect a privacy policy, and many laws require one. It tells visitors what you gather, why, who you share it with, and how they reach you. Payment processors, ad networks and app stores also ask to see one before they will work with you. A clear policy is a basic trust signal, not a legal nicety.

What this generator actually does

You answer questions in plain language: your business name, what data you collect, which tools you use, whether you sell data, and how visitors can contact you. The tool slots your answers into a structured draft covering the sections people expect to see. You get an editable document, not a locked PDF. Read every line, change anything that does not match how your business really works, then publish it on your own site.

Cookies, analytics and tracking

Most sites set cookies without the owner realising, through analytics, embedded video, live chat or ad pixels. This generator includes a cookie section that lists the common categories, essential, analytics, and marketing, so you can describe what your site uses. It does not scan your site or detect cookies for you. You tell it what you have, and it writes the section. If you are unsure what your site sets, a browser cookie inspector will show you.

Keep it current as your business changes

A privacy policy is not write-once. Every time you add a tool, a new form, a chat widget or a different analytics provider, the data you handle changes, and your policy should follow. Generate a fresh draft whenever something material shifts, and date it so visitors can see when it last changed. An out-of-date policy that describes tools you no longer use can be worse than none at all.

Not sure what your site sets?

The cookie checker shows what your site sets before anyone clicks Accept

Questions

Is the generated privacy policy legally compliant?
No tool can promise that, and this one does not. It gives you a solid starting draft covering the sections people expect, but compliance depends on your business, your data, and which laws apply to you. Have a solicitor or attorney review it before you rely on it, especially if you handle sensitive or regulated data.
Does it cover GDPR and US state laws like CCPA?
The draft includes sections that reflect common requirements, but it does not certify compliance with UK GDPR, CCPA/CPRA or the roughly twenty other US state privacy laws now in force. Laws differ by state and country and keep changing. Use the draft as a base and get it reviewed for the jurisdictions you actually serve.
Is my information sent to your servers?
No. The generator runs entirely in your browser. Your answers are used to assemble the draft on your own device and are not transmitted to us or saved anywhere. Close the tab and nothing is retained.
Can I edit the policy after generating it?
Yes, and you should. The output is plain, editable text, not a locked file. Read every line, remove anything that does not match your business, and add anything specific to how you operate. It is your document.
Who is qualified to check my final policy?
A solicitor (UK) or attorney (US) who works in data protection or privacy law. For context, a member of our team is a certified ISO 27001 Lead Auditor and ISO 42001 Auditor, which informs how we structure the template, but that is not legal advice and does not replace a lawyer reviewing your specific situation.