P freeprivacypolicy.app
Blog

What is a privacy policy?

A privacy policy is a public document that tells visitors what data you collect, how you use it, and who you share it with.

By FreePrivacyPolicy Editorial Team · Privacy compliance editors · Privacy Basics · 8 min read

Generate your privacy policy Free · no signup · hosted public URL

The one-sentence answer

A privacy policy is a public document that tells visitors what personal data you collect, how you use it, who you share it with, and what rights they have over their data. It is required by GDPR (EU), CCPA (California), LGPD (Brazil), the App Store, Google Play, and most ad networks.

What every privacy policy must contain

  1. Who you are — legal name and contact email
  2. What data you collect — categories, not raw values
  3. Why you collect it — purposes, mapped to legal basis under GDPR Article 6
  4. Who you share it with — every third-party SDK and service
  5. How long you keep it — retention periods per category
  6. What rights users have — access, deletion, portability, opt-out
  7. How to contact you — for data subject requests
  8. When the policy was last updated

What a privacy policy is not

  • It is not a cookie banner — that's for managing consent
  • It is not terms of service — that's for defining the deal
  • It is not a Data Processing Agreement — that's a B2B contract
  • It is not legally binding on the user — it binds you

What happens if you do not have one

Three consequences. (1) Regulator fines: GDPR up to €20M or 4% of turnover; CCPA up to $7,500 per intentional violation. (2) App store rejection: Apple and Google both reject submissions without a working privacy policy URL. (3) Loss of ad revenue: AdMob, AdSense, Meta, and most networks suspend accounts that fail policy checks.

Ready to publish?

Answer six questions, get a hosted public URL the App Store, Google Play, and ad networks accept. No credit card.

Generate your privacy policy

Frequently asked questions

Is a privacy policy the same as a privacy notice?
In practice, yes. GDPR uses "privacy notice" for the document presented to data subjects; many companies call the same document a "privacy policy". The contents must be the same.
Can I copy another company's privacy policy?
No — copyright applies, and their data flows are not yours. Use a generator.

Related reading