Privacy Policy

rshankras/claude-code-apple-skills/skills/legal/privacy-policy

作者 rshankras9ffb83138209无许可证784 个星标收录于 2026年10月9日更新于 2026年10月9日仓库2个月前更新

Generate privacy policies, terms of service, and EULAs for Apple platform apps. Detects data collection patterns, third-party SDKs, and generates region-specific legal documents with Apple Privacy Nutrition Label mapping. Use when user needs legal documents or data collection disclosure for App Store submission.

仅含说明Business & Finance
AI 生成的概览

为 Apple 平台应用生成隐私政策、服务条款和最终用户许可协议,并映射 App Store 隐私标签。

功能
该技能会检查应用项目中的第三方 SDK、数据收集模式和 Info.plist 权限说明,然后询问所需文档、收集的数据、使用的服务、儿童数据以及托管方式等配置问题。它根据模板组装 Markdown 法律文档,加入针对 GDPR、CCPA、DPDP 和 COPPA 的地区条款,并生成 Apple 隐私营养标签映射和集成清单。输出写入 docs 文件夹,或为应用内及网站托管做好准备。
适用场景
当应用需要隐私政策、服务条款或最终用户许可协议时使用,尤其是为提交 App Store 做准备。也适用于新增分析、广告或崩溃报告后需要更新披露内容,或涉及数据收集披露、隐私合规及 Apple 隐私营养标签的问题。
运行要求
仅包含说明,不含脚本。依赖文件读取、写入、编辑、glob、grep 和用户提问工具,并读取随附的 templates.md 文件。无需凭据或网络访问。

Privacy Policy & Legal Document Generator

Generate ready-to-use privacy policies, terms of service, and EULAs tailored to your app's data practices, third-party services, and target markets.

Disclaimer: This skill generates template legal documents based on common indie app scenarios. Consult a qualified lawyer for apps handling sensitive data (health, financial, children's data), apps with complex data sharing arrangements, or apps operating in highly regulated industries. These templates are a strong starting point -- not a substitute for legal counsel.

When This Skill Activates

Use this skill when the user:

  • Needs a privacy policy for their app
  • Needs terms of service or EULA
  • Apple requires a privacy policy for App Store submission
  • Is adding analytics, ads, or crash reporting and needs to update their privacy policy
  • Asks about data collection disclosure or privacy compliance
  • Mentions GDPR, CCPA, DPDP, or COPPA requirements for their app
  • Wants to know what to declare in Apple's Privacy Nutrition Labels

Pre-Generation Checks

Before generating documents, gather context from the project.

1. Look for Existing Legal Documents

Glob: **/privacy*.md, **/privacy*.html, **/privacy*.txtGlob: **/terms*.md, **/terms*.html, **/terms*.txtGlob: **/eula*.md, **/eula*.html, **/eula*.txtGlob: **/legal/**

If existing documents found, ask user whether to replace or update them.

2. Check for Third-Party SDK Usage

Grep: "Firebase" or "GoogleAnalytics" or "Crashlytics"Grep: "Mixpanel" or "Amplitude" or "PostHog"Grep: "AdMob" or "AppLovin" or "UnityAds"Grep: "FacebookSDK" or "GoogleSignIn" or "SignInWithApple"Grep: "Sentry" or "Bugsnag" or "DataDog"Grep: "RevenueCat" or "Adapty" or "Qonversion"Grep: "TelemetryDeck" or "Plausible" or "CountlySDK"

Note detected SDKs to auto-populate data collection sections.

3. Detect Data Collection Patterns in Code

Grep: "UserDefaults" -- Local preferences storageGrep: "CoreData" or "SwiftData" or "NSPersistentContainer" -- Local databaseGrep: "CloudKit" or "CKContainer" -- Cloud syncGrep: "URLSession" or "Alamofire" -- Network callsGrep: "HealthKit" or "HKHealthStore" -- Health dataGrep: "CLLocationManager" or "CoreLocation" -- Location dataGrep: "AVCaptureSession" or "PHPhotoLibrary" -- Camera/photosGrep: "Contacts" or "CNContactStore" -- Contacts accessGrep: "ATTrackingManager" -- App Tracking TransparencyGrep: "ASAuthorizationAppleIDProvider" -- Sign in with Apple

4. Check Info.plist for Permission Usage Descriptions

Grep: "NSCameraUsageDescription" or "NSPhotoLibraryUsageDescription"Grep: "NSLocationWhenInUseUsageDescription" or "NSLocationAlwaysUsageDescription"Grep: "NSHealthShareUsageDescription" or "NSHealthUpdateUsageDescription"Grep: "NSContactsUsageDescription" or "NSMicrophoneUsageDescription"Grep: "NSUserTrackingUsageDescription"

Configuration Questions

Ask the user via AskUserQuestion:

1. What documents do you need?

  • Privacy Policy only
  • Terms of Service only
  • EULA only
  • All three (recommended for App Store apps)

2. What data does your app collect?

  • No user data (fully offline, no accounts)
  • Anonymous analytics only (usage events, crash data)
  • Account with email (sign-in required)
  • Account with personal info (name, email, profile, preferences)
  • Health or financial data (triggers additional compliance sections)

3. What third-party services does your app use?

  • None
  • Analytics only (e.g., TelemetryDeck, Firebase Analytics)
  • Analytics + crash reporting (e.g., Sentry, Crashlytics)
  • Advertising (e.g., AdMob, AppLovin)
  • Social login (e.g., Sign in with Apple, Google Sign-In)
  • Multiple of the above (list them)

4. Does your app target or allow children under 13?

  • No
  • Yes (triggers COPPA section and stricter data practices)

5. Where will you host these documents?

  • GitHub Pages (free, Markdown to HTML)
  • In-app (Settings screen with WKWebView or Text view)
  • Personal/company website
  • All of the above (recommended -- Apple requires a publicly accessible URL)

Generation Process

Step 1: Select Template Sections

Read templates.md for the document templates.

Based on configuration answers, include or exclude sections:

AnswerSections Added
No user dataMinimal privacy policy (no collection, no sharing)
Anonymous analyticsAnalytics disclosure, third-party services list
Account with emailAccount data, authentication, data retention
Personal infoFull data collection, user rights, data portability
Health/financialSensitive data handling, enhanced security, additional consent
Children under 13COPPA section, parental consent, limited data collection

Step 2: Fill in App-Specific Details

Replace template placeholders with detected or user-provided values:

  • [APP_NAME] -- App display name
  • [DEVELOPER_NAME] -- Developer or company name
  • [CONTACT_EMAIL] -- Privacy contact email
  • [EFFECTIVE_DATE] -- Document effective date
  • [WEBSITE_URL] -- Developer website or privacy page URL

Step 3: Add Region-Specific Sections

Include sections based on target markets:

GDPR (European Union users):

  • Data controller identification
  • Lawful basis for processing (consent, legitimate interest, contract)
  • Data subject rights (access, rectification, erasure, portability, objection)
  • Data Protection Officer contact (if applicable)
  • Data retention periods
  • Right to lodge complaint with supervisory authority

CCPA (California users):

  • Categories of personal information collected
  • Business purposes for collection
  • "Do Not Sell or Share My Personal Information" notice
  • Right to know, delete, and opt-out
  • Non-discrimination for exercising rights
  • Financial incentive disclosure (if applicable)

DPDP (India users):

  • Data fiduciary identification
  • Purpose of data processing
  • Consent mechanism
  • Data principal rights (access, correction, erasure, grievance redressal)
  • Data retention limitations
  • Processing of children's data (under 18)

COPPA (children under 13):

  • Parental consent requirement
  • Limited data collection (only what is strictly necessary)
  • No behavioral advertising to children
  • Parental rights (review, delete, refuse further collection)
  • Safe harbor program compliance (if applicable)

Step 4: Generate Apple Privacy Nutrition Label Mapping

Based on detected data practices, generate a mapping for App Store Connect:

Apple Privacy Nutrition Label Mapping=====================================
Data Types to Declare:- [ ] Contact Info: Email Address -- Used for: App Functionality, Account- [ ] Identifiers: User ID -- Used for: App Functionality- [ ] Usage Data: Product Interaction -- Used for: Analytics- [ ] Diagnostics: Crash Data -- Used for: App Functionality- [ ] Diagnostics: Performance Data -- Used for: Analytics
Data Linked to User: [List items linked to user identity]Data Used to Track: [List items used for cross-app tracking, if any]
Tracking: [Yes/No -- triggers ATT requirement if Yes]

Step 5: Output Documents

Generate documents in Markdown format. Place files based on user's hosting preference:

  • GitHub Pages: docs/privacy-policy.md, docs/terms-of-service.md, docs/eula.md
  • In-app: Resources/Legal/privacy-policy.md, etc.
  • Website: Output to clipboard/file for manual upload
  • All: Generate in docs/ with guidance for in-app integration

Apple-Required Privacy Disclosures

App Store Connect Privacy Questions

When submitting to the App Store, Apple asks about data practices. Map generated privacy policy to these questions:

Apple QuestionWhere to Find Answer
Do you or your third-party partners collect data?"Information We Collect" section
Data types collectedPrivacy Nutrition Label mapping (Step 4)
Is data linked to user identity?"How We Use Information" section
Is data used for tracking?"Third-Party Services" section

Privacy Nutrition Labels

Declare these data types based on your app's practices:

If Your App...Declare These Types
Has user accountsContact Info, Identifiers
Uses analyticsUsage Data (Product Interaction)
Has crash reportingDiagnostics (Crash Data, Performance Data)
Shows adsIdentifiers (Device ID), Usage Data
Uses locationLocation (Precise or Coarse)
Accesses photosPhotos or Videos
Accesses health dataHealth & Fitness
Uses Sign in with AppleContact Info (Email), Identifiers (User ID)

When ATT (App Tracking Transparency) Is Required

Required for: IDFA access, linking user data with third-party data for advertising, or sharing user data with data brokers. Not required for first-party server-side analytics, crash reporting, fraud detection, or non-IDFA attribution (e.g., SKAdNetwork).

Hosting Guidance

GitHub Pages (Free, Recommended for Indie Devs)

  1. Create docs/ folder in your repo
  2. Add privacy-policy.md, terms-of-service.md, eula.md
  3. Enable GitHub Pages in repo Settings > Pages > Source: /docs
  4. Your URL: https://yourusername.github.io/yourapp/privacy-policy

In-App Display

swift
// Option 1: WKWebView for hosted HTMLimport WebKit
struct LegalDocumentView: UIViewRepresentable {    let url: URL
    func makeUIView(context: Context) -> WKWebView { WKWebView() }    func updateUIView(_ webView: WKWebView, context: Context) {        webView.load(URLRequest(url: url))    }}
// Option 2: Bundled Markdown rendered as Textstruct PrivacyPolicyView: View {    var body: some View {        ScrollView {            Text(LocalizedStringKey(privacyPolicyMarkdown))                .padding()                .textSelection(.enabled)        }        .navigationTitle("Privacy Policy")    }}

Apple Requirements for Privacy Policy URL

  • Must resolve publicly (not behind login or in-app only) at all times -- Apple checks during review and requires it under App Store Connect's "App Privacy"
  • Must also be accessible from within the app (Settings or About screen)

Output Format

After generation, provide:

Files Created

docs/ ├── privacy-policy.md     # Privacy policy with region-specific sections ├── terms-of-service.md   # Terms of service (if requested) └── eula.md               # End-user license agreement (if requested)

Apple Privacy Nutrition Label Checklist

Provide a checklist the user can follow in App Store Connect.

Integration Checklist

  • Host documents at a publicly accessible URL
  • Add privacy policy URL to App Store Connect
  • Add legal links to app Settings or About screen
  • Complete Privacy Nutrition Labels in App Store Connect
  • If using ATT, add NSUserTrackingUsageDescription to Info.plist
  • Test that privacy policy URL loads correctly
  • Set a calendar reminder to review documents annually

References

  • templates.md -- Full legal document templates with placeholders
  • Related: generators/consent-flow -- GDPR/CCPA consent UI generation
  • Related: generators/account-deletion -- Account deletion flow (App Store requirement)
  • Related: generators/permission-priming -- Pre-permission UI for ATT
  • Related: monetization/ -- Subscription terms and pricing disclosures
  • Apple App Review Guidelines Section 5.1 (Privacy)
  • Apple App Store Connect Privacy Details documentation

来源与署名

来源:rshankras/claude-code-apple-skills位于skills/legal/privacy-policy提交9ffb831

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架