Privacy Policy Generator USA
No federal privacy statute - a growing patchwork of state laws, plus FTC Section 5 and the wiretapping class-action risk.
A US privacy policy is a compliance document and a liability document at the same time. It has to satisfy the state laws you fall under, and it has to be literally true, because the FTC enforces the gap between what you say and what you do.
The United States has no general federal privacy law. What it has instead is a widening set of comprehensive state statutes - California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota and Maryland among them - layered over sectoral rules for health, finance, education and children.
Above all of them sits Section 5 of the FTC Act. The FTC does not need a privacy statute to act: if your policy says one thing and your product does another, that is a deceptive practice, and the resulting consent orders run for twenty years. A US privacy policy is therefore best understood as a promise you will be held to literally.
The most expensive US privacy risk for a small business is not usually a regulator. It is private litigation under old wiretapping statutes - California’s CIPA in particular - repurposed against session replay, chat widgets and advertising pixels. That risk turns on consent and disclosure, which is exactly what the policy and banner control.
What a privacy policy in the United States has to cover
Categories of personal information collected, the sources, and the business purposes - in the structure state laws expect
Whether you sell or share personal information for targeted advertising, with a working opt-out and GPC handling
Rights of access, deletion, correction, portability and appeal, with the response deadlines each state sets
Sensitive personal information: what you collect and the limit-use route where a state provides one
The date of the last review, which several state laws require to be within the past twelve months
If you use session replay, chat transcription or advertising pixels, say so plainly and early. That disclosure is the difference between a defensible practice and the fact pattern in a wiretapping complaint.
How the United States actually moves personal data
Advertising pixels and conversion APIs
Meta, Google and TikTok pixels plus server-side conversion APIs move identifiable data to ad platforms. Under most state laws this is "sharing for targeted advertising" and needs an opt-out; under CIPA theories it is the basis of the complaint.
Session replay and chat tooling
Tools that record keystrokes, mouse movement or chat content are the highest-frequency source of US privacy class actions. Disclosure before the recording starts is the defence.
Data broker and enrichment inflows
Buying enrichment data makes you a recipient of third-party personal information, which several state laws require you to disclose - and California’s Delete Act may make you a registered data broker.
Health-adjacent data outside HIPAA
Wellness, fitness and symptom data usually falls outside HIPAA but inside Washington’s My Health My Data Act, which carries a private right of action.
Children and teens
COPPA applies under 13; several state laws add duties for teens, and age-appropriate design codes impose obligations that go well past a checkbox.
Third parties the draft will ask you about
Stripe · Shopify Payments · Google Analytics 4 · Meta Pixel · Klaviyo · HubSpot · Twilio and SendGrid · AWS us-east-1 · Intercom · Segment
The rules that apply
State comprehensive privacy laws
Seventeen-plus states with rights of access, deletion, correction, portability and opt-out of targeted advertising and sale, with thresholds that catch mid-sized businesses.
FTC Act Section 5
Unfair or deceptive acts and practices. Your published statements are enforceable commitments regardless of any privacy statute.
Sectoral statutes
HIPAA for covered entities, GLBA for financial institutions, FERPA for education records, COPPA for under-13s, and the VPPA for video viewing histories.
Wiretapping and pen-register claims
CIPA in California and analogous state statutes drive class actions over session replay, chat transcription and pixel-based tracking.
Global Privacy Control
California, Colorado, Connecticut and others require honouring an opt-out preference signal from the browser, not just a link on the site.
What the generated privacy policy contains
Identity and contact details of the controller
Your legal entity, trading name, registered address and a working contact route - plus a representative or DPO where one is required.
Categories of personal data and their sources
What you collect directly, what you observe automatically, and what you receive from third parties such as payment providers or ad platforms.
Purposes and lawful basis, purpose by purpose
A table that pairs each processing purpose with its lawful basis rather than listing all six bases and hoping one fits.
Recipients and sub-processors
The categories of recipient, and for the ones that matter to users - payment, hosting, analytics, support - the named provider.
International transfers and their safeguards
Where data leaves its home jurisdiction, and the mechanism relied on: adequacy, standard contractual clauses, the UK addendum or IDTA.
Retention periods per data category
Concrete periods or the criteria used to set them, which is what regulators ask for first when a complaint lands.
Rights and how to exercise them
Access, rectification, erasure, portability, objection and restriction, with the actual route to make a request and the deadline you work to.
Complaints and supervisory authority
The regulator a user can escalate to, named, with a link - not a generic "your local authority".
Building a US-facing policy
Work out which state laws you actually meet the threshold for
Most turn on residents processed per year plus revenue, and several drop the threshold where you derive revenue from selling data.
Inventory every tag before you write the disclosure
The list of tags is the list of disclosures. Anything you cannot see, you cannot describe accurately.
Implement opt-out end to end
The link, the preference signal, and the downstream propagation to ad platforms through their limited-data-use or restricted-processing settings.
Reconcile the policy against the product line by line
This is what an FTC investigation does, so do it first.
Set an annual review date and record it
Some state laws require it, and it is the cheapest possible evidence of a compliance programme.
Where this usually goes wrong
Promising more than the product does
A line like "we never share your data with third parties" alongside a live Meta pixel is a Section 5 case with no privacy statute required.
A "Do Not Sell" link that does nothing
Several state attorneys general have opened enforcement on exactly this: a link that renders a form which never reaches the ad platforms.
Ignoring browser opt-out signals
Global Privacy Control has to be honoured where state law requires it. A site with a compliant link and no GPC handling is only half done.
Treating one state law as covering all of them
Thresholds, definitions of sale, cure periods and universal opt-out obligations differ. A Virginia-shaped notice will not satisfy California.
Session replay with no pre-collection notice
Notice after the fact does not help. The consent has to be obtainable before the recording tool loads.
Frequently asked questions
Is there a federal US privacy law?
No general one. There are sectoral laws - HIPAA, GLBA, FERPA, COPPA, the VPPA - and Section 5 of the FTC Act, which reaches any business whose privacy statements are misleading.
Do I need to comply with every state law?
Only the ones whose thresholds you meet, but the practical answer for most growing businesses is to build to the strictest applicable standard - usually California - and treat the rest as variations.
What is the Global Privacy Control?
A browser-level signal that communicates an opt-out of sale and targeted advertising. California, Colorado and Connecticut among others require businesses to honour it as a valid request.
Why are companies being sued over website chat and analytics?
Plaintiffs use decades-old wiretapping and pen-register statutes, especially California’s CIPA, arguing that third-party tools intercept communications without consent. Clear pre-collection disclosure and consent are the practical defence.
Is a privacy policy legally required?
If you process personal data, in almost every market yes. GDPR and UK GDPR require the disclosure at the point of collection, CCPA/CPRA requires a notice at collection plus an annually reviewed policy, and app stores and payment processors require a public policy URL before they will list or onboard you.
Can I copy another company’s privacy policy?
It is both a copyright problem and a compliance problem. A copied policy describes someone else’s data flows, processors and retention periods, so it is inaccurate the moment you publish it - and an inaccurate transparency notice is itself a breach of GDPR Article 13.
How often does a privacy policy need updating?
Whenever your processing changes - a new analytics tool, a new payment provider, a new market - and as a backstop, review it annually. CPRA makes the twelve-month review explicit.
Does PolicifyAI give legal advice?
No. PolicifyAI is a technology provider, not a law firm. The output is a structured, jurisdiction-aware draft that a qualified adviser should review before you rely on it.
Privacy Policy Generator USA
Answer a short questionnaire and get a draft written for the United States. Free to start, no card required.
Generate your privacy policyOther documents for the United States
Each one is written for the same context, not a generic template.
The same document, by country
Go deeper
PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.