# Privacy policy from your code (/legal--privacy-policy)

/legal--privacy-policy is a Claude Code skill in the Business section. Drafts a privacy policy from the data collection, third parties and retention actually found in your codebase.

- Web version: https://skills.sgomez.dev/en/s/legal--privacy-policy
- Section: [Business](https://skills.sgomez.dev/en/business.md)
- Author: Santiago Gómez de la Torre
- License: MIT
- Source: https://github.com/sgomez-dev/claude-skills/blob/main/skills/legal/privacy-policy.md
- Updated 10 Jul 2026

## Use it when

- You need a privacy policy that describes what your product really does
- You want to map what data you collect and which third parties receive it
- You want to catch contradictions between the policy and the code

## Not for

- Replacing the advice of a lawyer
- Inventing company details: anything unverified stays as [PLACEHOLDER]

## What you get

A legal/PRIVACY_POLICY.md file in plain language; in the chat, the data-mapping table and a list of discrepancies to fix in the product.

## How to ask for it

- `/legal--privacy-policy generate the privacy policy for my app`
- `/legal--privacy-policy scan the code and draft the privacy notice`
- `/legal--privacy-policy I need a privacy policy based on my actual data practices`

## Install

macOS · Linux:

```
curl -fsSL https://raw.githubusercontent.com/sgomez-dev/claude-skills/main/install.sh | bash
```

Windows:

```
irm https://raw.githubusercontent.com/sgomez-dev/claude-skills/main/install.ps1 | iex
```

Claude Code plugin:

```
/plugin marketplace add sgomez-dev/claude-skills
/plugin install legal-skills@claude-skills-collection
```

## Permissions

- Reads: `**/*`
- Writes: `legal/**`, `PRIVACY_POLICY*.md`
- Runs: —
- Network: No
- Destructive: No

## Author's description

Draft a privacy policy from the data practices actually found in your codebase

## Questions about this skill

### Is it based on my code or a template?

It scans forms, models, logs, SDKs and dependencies, and each clause is meant to map to evidence found.

### What about things it cannot know?

Company details, addresses or retention periods with no basis in code are marked [PLACEHOLDER] or [CONFIRM] and kept visible.

### Does it cover several regulations?

Yes. If, say, GDPR and California both apply, it writes one policy with regime-specific subsections.


- [How we review this](https://skills.sgomez.dev/en/methodology.md)
