Illustrative sample document

Privacy Policy sample for an AI SaaS product (illustrative)

A complete privacy policy generated by the Legal Policy Generator clause engine for Example Draft, a fictional AI writing assistant for teams operated by Example Software Ltd. Prompts are processed by Anthropic models, conversation history is stored, content is not used for model training, subscriptions run through Stripe, and EU, UK, and US state modules are active.

Illustrative example for a fictional business. This document was generated by the Legal Policy Generator clause engine from invented facts about a business that does not exist. Do not copy it as-is: it describes the fictional business's practices, not yours, and it is not legal advice.

Generate your own Privacy Policy

Facts supplied for this fictional business

SaaS platform with accounts, payments, and user content; identity, account content, technical usage, and payment data; transactional email through Postmark; privacy-focused analytics through Plausible; no advertising; recurring Stripe payments without card storage; adult audience; EU GDPR, UK GDPR, and other US state modules with no sale or sharing; AI processing through Anthropic with stored prompts and outputs, no training use, no significant automated decisions, and an opt-out in workspace settings.

Privacy Policy

Privacy Policy for Example Draft

Effective date
2026-09-23

Introduction

This Privacy Policy explains how Example Software Ltd (fictional) processes personal information in connection with Example Draft at https://example.org. It takes effect on 2026-09-23. It is based on the service practices described by its operator and should be read together with notices shown when information is collected.

Who operates this service

Example Software Ltd (fictional) is the business responsible for this policy and is established in the United Kingdom, with a postal address at 3 Example Road, Example Town.

Scope

This policy applies to the software-as-a-service platform offered under the Example Draft name. It does not govern independent third-party services that publish their own privacy terms.

Information we collect

Depending on use of the service, Example Software Ltd (fictional) collects these broad categories: identity and contact information; account information, submitted content, and communications; technical, usage, and device information; and payment, location, sensitive, or other information. Specific data depends on the features used and the practices described below.

Some information is required to provide requested features; if it is not supplied, those features may be unavailable.

Sources of information

Information comes from users directly and automatic collection from the devices used to access the service. Information received from another source is handled for the purposes described in this policy and subject to applicable restrictions.

How we use information

Information is used for providing and securing the service; managing accounts, support, payments, and communications; and analytics and product improvement. It may also be used to prevent misuse, establish or defend legal claims, meet legal obligations, and enforce service terms where those activities are relevant and permitted.

Messages and email

The service sends transactional service messages using Postmark. Contact details are used for delivery, service administration, and the purposes described when the details are collected.

Transactional messages are sent only as needed to provide, secure, or administer the service. The operator does not measure message opens or link interactions.

Cookies and tracking technologies

The service uses essential browser storage or cookies only where needed for security, sessions, saved choices, load balancing, or requested functionality. These technologies are not used for cross-service advertising.

Analytics

The service uses privacy-focused analytics with Plausible to understand service operation, usage, errors, and improvements. Analytics data may include technical, device, interaction, approximate-location, and identifier information according to the selected configuration and provider controls.

Payments

Payments are processed using Stripe for recurring subscriptions. The operator does not directly store full payment-card information; the payment provider handles card details under its own privacy terms.

Artificial intelligence processing

Example Draft uses artificial intelligence for workspace drafting and summarization. To provide these features, the service sends the following information to Anthropic: the prompts and documents a user submits to the AI features.

People who use these features interact with an AI system, and responses or other content produced by these features are generated by AI. AI-generated content can be inaccurate or incomplete and should be checked before it is relied on.

Prompts, submitted content, or outputs of the AI features are stored. The operator describes how long the service and the AI providers keep them as follows: prompts and outputs stay in the workspace until the user deletes them.

The operator states that information submitted to the AI features is not used to train AI models, by the operator or by the AI providers under the terms that apply to the service. The operator states that people at the operator and the AI providers do not review prompts, submitted content, or outputs.

The operator states that the service asks for the user's permission before personal data is shared with a third-party AI provider.

The operator states that AI is not used to make decisions that produce legal or similarly significant effects on people.

Choices about the AI features: available by turning off AI features in workspace settings. Questions and privacy requests about information processed by the AI features can be sent to privacy@example.org.

Sharing and disclosures

Information may be disclosed to service providers and authorities or professional advisers for the purposes described in this policy, subject to contracts and legal limits where required. It may also be disclosed to authorities, courts, advisers, or transaction counterparties when reasonably necessary for law, safety, claims, or a business reorganization. Selected service providers include AWS, Stripe, Anthropic, and Sentry.

The operator states that it does not sell personal information or share it for cross-context behavioral advertising as those terms are defined by applicable United States privacy laws. Ordinary disclosures to service providers, legal recipients, and user-directed recipients are not treated as a sale when statutory conditions are met.

International transfers

Information may be processed outside the United Kingdom. The stated location and safeguard approach is: standard contractual clauses and the UK International Data Transfer Addendum. For EU information, the transfer mechanism is: standard contractual clauses and the UK International Data Transfer Addendum. Users may request information about the mechanism used. For UK information, the transfer mechanism is: standard contractual clauses and the UK International Data Transfer Addendum. Users may request information about the mechanism used.

Data retention

The retention model is: records are kept while the account or relationship remains active and for a justified period afterward. Records may be kept longer when reasonably necessary for security, disputes, tax, accounting, fraud prevention, legal obligations, or enforcement. Deletion or de-identification follows the stated model and applicable law.

Security

The operator uses encryption, access restrictions, and backups and monitoring, selected according to the nature and risk of the information. No transmission or storage method is completely secure, so absolute security cannot be guaranteed.

Children's privacy

The service is intended for adults only. If the operator learns that information was collected from a child contrary to the stated audience or applicable law, it will take reasonable steps to delete it and may ask for age or authority verification.

Your choices and privacy rights

Depending on location and processing, users may ask to access, correct, delete, restrict, or receive information; withdraw consent; unsubscribe; object; or opt out of sale, sharing, or targeted advertising. Requests are supported through the account settings or by email to privacy@example.org. The operator may verify identity and authority, apply legal exceptions, and explain a denial and available appeal where required.

European Economic Area privacy rights

The EU GDPR has applied since May 25, 2018. Where it applies, people may request access, rectification, erasure, restriction, and portability; object to processing; withdraw consent for future processing; and complain to the competent supervisory authority. Rights depend on the processing, lawful basis, and statutory exceptions. Requests may be made through the account settings or at privacy@example.org.

United Kingdom privacy rights

Where the UK GDPR and Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025, apply, people may request access, rectification, erasure, restriction, and portability; object to processing; withdraw consent for future processing; and complain to the UK Information Commissioner's Office. Rights depend on the processing, lawful basis, and statutory exceptions. Requests and data-protection complaints may be made through the account settings or at privacy@example.org. The operator will acknowledge a data-protection complaint within 30 days, take appropriate steps to investigate without undue delay, keep the complainant informed, and communicate the outcome.

United States privacy disclosures

United States privacy duties vary by state, sector, data type, and business activity. This policy describes selected factual practices and adds state-specific rights only where the operator identified those laws as applicable. It does not claim that one nationwide GDPR-equivalent framework governs every user or processing activity.

Other United States state privacy rights

Several United States states have comprehensive consumer privacy laws, such as the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, and the Texas Data Privacy and Security Act. Whether one of these laws, or a similar law of another state, applies depends on the consumer's state of residence, the operator's activities, the law's thresholds, and its exemptions. This section summarizes rights and practices under those laws and does not expand or waive any statutory right.

Where such a law applies, residents may, subject to its definitions and exceptions, confirm whether their personal data is processed and access it, correct inaccuracies, delete personal data, obtain a portable copy, and opt out of processing for targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects. Requests can be submitted through the account settings or by email to privacy@example.org. The operator may need to verify the identity of the person making a request.

For these laws, the categories of personal data processed are identity and contact information; account information, submitted content, and communications; technical, usage, and device information; and payment, location, sensitive, or other information, and the purposes of processing are providing and securing the service; managing accounts, support, payments, and communications; and analytics and product improvement. The operator describes the personal data it shares with third parties, and the categories of those third parties, as follows: account, workspace, and billing information is shared with hosting, AI, payment, and error-monitoring providers that process it for the service; no personal data is sold.

The operator states that it does not process sensitive data as these laws define it, such as precise geolocation, health, genetic or biometric data, or data revealing racial or ethnic origin or religious beliefs.

If the operator declines to act on a request made under a state privacy law, the consumer may appeal that decision. Appeals can be submitted as follows: email the privacy contact with the subject line Privacy appeal. The operator responds to an appeal in writing within the period set by the applicable state law and explains the action taken or not taken.

If an appeal is denied, the consumer may submit a complaint to the Attorney General of the consumer's state of residence. Where the applicable law requires it, the appeal decision identifies an online mechanism, if available, or another method for contacting the Attorney General.

Account and data deletion

Users can request account and associated-data deletion through email to privacy@example.org or the account settings. Some records may remain for security, legal, tax, payment, dispute, fraud-prevention, or backup-cycle needs and will remain restricted to those purposes.

Changes to this policy

This policy may be updated to reflect service, legal, or operational changes. The current version will be posted at https://example.org with a revised effective date. Additional notice or consent will be provided only when required by applicable law.

Contact us

Privacy questions and requests may be sent to Example Software Ltd (fictional) at privacy@example.org or by mail to 3 Example Road, Example Town.