legal-page-generator
When the user wants to create, optimize, or structure legal pages (Privacy, Terms, etc.). Also use when the user mentions "privacy policy," "terms of service," "legal pages," "cookie policy," "terms and conditions," "legal footer," "legal section," "compliance pages," or "legal requirements." For Privacy Policy content, use privacy-page-generator. For Terms of Service, use terms-page-generator. For Cookie Policy, use cookie-policy-page-generator.
What this skill does
# Pages: Legal Guides legal page content, structure, compliance, and platform readiness for AI/SaaS products. **When invoking**: On **first use**, if helpful, open with 1–2 sentences on what this skill covers and why it matters, then provide the main output. On **subsequent use** or when the user asks to skip, go directly to the main output. ## Initial Assessment Identify: 1. **Product category**: Free anonymous, free with account, freemium, subscription SaaS, enterprise/B2B, API/developer, marketplace/platform, e-commerce, content/media, mobile app, AI agent/MCP — see §Product Categories 2. **Page type**: Privacy Policy, Terms of Service, Cookie Policy, etc. 3. **Jurisdiction needs**: Which countries' laws apply — see §Jurisdiction Decision Framework 4. **Indexing strategy**: Index or noindex — see §Indexing Strategy 5. **Platform dependencies**: Which external platforms require these pages — see §Platform Dependencies --- ## Product Categories The legal page structure depends heavily on the product category. Identify which one applies before drafting: | Category | Key Legal Characteristics | Sections to INCLUDE | Sections to SKIP | |---|---|---|---| | **Free Anonymous** | No accounts, no payment, no persistent storage, GA4 analytics | What we DON'T collect, no-training statement, fair-use limits, free/no-SLA | Payment, account responsibilities, refund, data portability | | **Free with Account** | Login required, user data stored, may have social features | Account security, data access/portability, user responsibilities | Payment, billing, refund | | **Freemium** | Free + paid tiers, payment data, auto-renewal | Payment terms, billing, tier differences, data handling per tier | — | | **Subscription SaaS** | Recurring billing, auto-renewal, cancellation | Payment, billing cycles, auto-renewal disclosure, cancellation process | — | | **Enterprise / B2B** | DPA, SOC 2, zero-training guarantees, SCCs | DPA reference, sub-processor list, security certifications, data processing roles, custom retention | Fair-use limits (usually N/A) | | **API / Developer** | Data processor role, rate limits, API keys | Rate limits, API key security, data processor terms, uptime/SLA | End-user account sections | | **Marketplace / Platform** | Multi-party, UGC responsibility, submission licensing | Content moderation, takedown process, submitter licenses, third-party content disclaimer | — | | **E-commerce** | Physical/digital goods, refunds, shipping | Refund policy, shipping policy, consumer rights, payment security | — | | **Content / Media** | Copyright, DMCA, content licensing | DMCA contact, content ownership, republication terms | Payment (unless paid content) | | **Mobile App** | App store review, privacy nutrition labels, permissions | App store compliance notes, permission justifications, data collection summary | — | | **AI Agent / MCP** | Automated decisions, tool invocation, sub-processor chains | AI decision transparency, sub-processor chain disclosure, autonomous action limits | — | --- ## Platform Dependencies Many external platforms **require** posted Privacy Policy and/or Terms of Service before the product can be listed, advertised, or operate in compliance. These should be flagged to the user during generation. ### Submission & Directory Platforms Most AI tool directories, MCP/Skills marketplaces, and software directories require both Privacy Policy and Terms of Service to be publicly accessible before a listing can be approved. Common requirements across these platforms: - Publicly linked Privacy Policy and Terms of Service - No illegal, deceptive, or IP-infringing content - Accurate, non-misleading product descriptions - Submitter warrants ownership or authority to list - Platform reserves right to reject or remove listings at discretion - Often require a DMCA/copyright complaint contact ### Advertising & Distribution Platforms | Platform | Requires | Consequence if Missing | |----------|----------|----------------------| | Google Ads | Privacy Policy link during account setup | Cannot launch campaigns | | Meta Ads (Facebook/Instagram) | Privacy Policy for ad account verification | Ad account suspended | | TikTok Ads | Privacy Policy for account review | Cannot launch | | Apple App Store | Privacy Policy URL + privacy nutrition labels | App rejected | | Google Play Console | Privacy Policy URL for all apps | App rejected | | LinkedIn Ads | Privacy Policy for business page verification | Restricted access | ### Infrastructure & Compliance | Requirement | What's Needed | |-------------|---------------| | Google Analytics ToS §7 | Posted privacy policy that discloses GA usage | | Stripe / payment processors | Privacy Policy URL during onboarding | | OAuth providers (Google, GitHub) | Privacy Policy URL for app verification | | SOC 2 / ISO 27001 | Both pages are standard vendor-assessment prerequisites | | Enterprise procurement | Both pages are due-diligence checklist items | | Accelerators (YC, Techstars, etc.) | Legal pages are standard application requirements | --- ## Jurisdiction Decision Framework Use a three-layer approach to determine which laws apply: **Layer 1 — Operator location** → determines primary governing law and venue in Terms. **Layer 2 — User locations** → determines which privacy regulations apply and whether regional supplements are needed. If the product is accessible globally, assume GDPR (EU), CCPA (California), and the operator's home jurisdiction at minimum. **Layer 3 — Data storage location** → determines data localization obligations. China (PIPL) and India (DPDP) may require local storage. ### Major Privacy Regulations (2025–2026) | Jurisdiction | Law | Consent Model | Max Penalty | Notable | |---|---|---|---|---| | EU/EEA | GDPR | Opt-in | €20M / 4% global revenue | 72h breach notification; DPO required for certain entities | | UK | UK GDPR + DPA 2018 | Opt-in | £17.5M / 4% | Post-Brexit independent; UK Representative required | | California | CCPA/CPRA | Opt-out | $7,988/violation (no cap) | 19 US states now enforce; ADMT rules effective Jan 2026 | | China | PIPL | Opt-in + separate consent for sensitive data | ¥50M / 5% revenue | **Data localization mandatory**; cross-border transfer requires security assessment | | Brazil | LGPD | Opt-in | R$50M (~$10M USD) | DPO required for larger orgs | | India | DPDP Act 2023 | Consent-centric | ₹250Cr (~$30M USD) | **Under-18 requires parental consent**; phased enforcement 2025–2027 | | Canada | PIPEDA + Quebec Law 25 | Opt-in | CAD $10M+ | Quebec has independent requirements | | South Korea | PIPA | Opt-in | 3% of revenue | Criminal penalties possible; among the strictest globally | | Japan | APPI | Opt-in for transfers | Criminal penalties | "Pseudonymized" data concept | | Australia | Privacy Act 1988 + 2025 amendments | Opt-in | AUD $50M+ | New "fair and reasonable" test; children's privacy code | ### Regional Supplements Pattern Follow the model used by leading AI platforms: one main policy covering universal practices, plus **regional supplement sections** for jurisdictions with unique requirements. At minimum, provide: - **EEA/UK Supplement**: GDPR legal bases (Art. 6), data subject rights (Art. 15–22), SCCs for transfers, DPO/representative contacts, complaint to supervisory authority - **California Supplement**: 11-category data collection table, right to know/delete/correct, "Do Not Sell or Share" statement, opt-out mechanisms Other regional supplements (China, Brazil, India, etc.) should be added when the product has significant users in those jurisdictions. ### Governing Law Patterns for Terms | Pattern | Use Case | Venue Clause | |---|---|---| | **Single jurisdiction** | Operator and users in same country | Governing law of [State], venue in [County] | | **Dual jurisdiction (fallback)** | Operator has ties to two countries | Primary: [Jurisdiction A]; Alternate: [Jurisdiction B] only where A is unavailable | | **EU-first** | Primarily
Related in Writing & Docs
jax-development
IncludedUse this skill when the user is writing, debugging, profiling, refactoring, reviewing, benchmarking, parallelising, exporting, or explaining JAX code, or when they mention JAX, jax.numpy, jit, grad, value_and_grad, vmap, scan, lax, random keys, pytrees, jax.Array, sharding, Mesh, PartitionSpec, NamedSharding, pmap, shard_map, Pallas, XLA, StableHLO, checkify, profiler, or the JAX repo. It helps turn NumPy or PyTorch-style code into pure functional JAX, fix tracer/control-flow/shape/PRNG bugs, remove recompiles and host-device syncs, choose transforms and sharding strategies, inspect jaxpr/lowering/IR, and benchmark compiled code correctly.
nature-article-writer
IncludedDrafts, rewrites, diagnostically critiques, and style-calibrates primary research manuscripts for Nature and Nature Portfolio journals. Use when the user wants a Nature-style title, summary paragraph or abstract, introduction, results, discussion, methods, figure legends, presubmission enquiry, cover letter, reviewer response, or when a scientific draft sounds generic, jargon-heavy, structurally weak, or AI-ish and needs precise, broad-reader-friendly prose without inventing data, analyses, or references. Best for primary research articles and letters rather than reviews or press releases unless explicitly adapting one.
deckrd
IncludedDocument-driven framework that derives requirements, specifications, implementation plans, and executable tasks from goals through structured AI dialogue. Use when user says "write requirements", "create spec", "plan implementation", "derive tasks", "structure this feature", "break down into tasks", or "document this module". Also use for reverse engineering existing code into docs (/deckrd rev). Do NOT use for direct code writing — use /deckrd-coder after tasks are generated. Do NOT use when the user only wants to run or fix existing code without planning.
clinical-decision-support
IncludedGenerate professional clinical decision support (CDS) documents for pharmaceutical and clinical research settings, including patient cohort analyses (biomarker-stratified with outcomes) and treatment recommendation reports (evidence-based guidelines with decision algorithms). Supports GRADE evidence grading, statistical analysis (hazard ratios, survival curves, waterfall plots), biomarker integration, and regulatory compliance. Outputs publication-ready LaTeX/PDF format optimized for drug development, clinical research, and evidence synthesis.
handling-sf-data
IncludedSalesforce data operations with 130-point scoring. Use this skill to create, update, delete, bulk import/export, generate test data, and clean up org records using sf CLI and anonymous Apex. TRIGGER when: user creates test data, performs bulk import/export, uses sf data CLI commands, needs data factory patterns for Apex tests, or needs to seed/clean records in a Salesforce org. DO NOT TRIGGER when: SOQL query writing only (use querying-soql), Apex test execution (use running-apex-tests), or metadata deployment (use deploying-metadata).
accelint-ac-to-playwright
IncludedConvert and validate acceptance criteria for Playwright test automation. Use when user asks to (1) review/evaluate/check if AC are ready for automation, (2) assess if AC can be converted as-is, (3) validate AC quality for Playwright, (4) turn AC into tests, (5) generate tests from acceptance criteria, (6) convert .md bullets or .feature Gherkin files to Playwright specs, (7) create test automation from requirements. Handles both bullet-style markdown and Gherkin syntax with JSON test plan generation and validation.