Illustrative sample document

Privacy Policy sample for a mobile app (illustrative)

A complete privacy policy generated by the Legal Policy Generator clause engine for Example Habits, a fictional habit-tracking app for adults operated by Example Apps Inc. The app has accounts, Firebase analytics, subscriptions sold through the app stores, transactional email, and CalOPPA and other US state disclosures.

Illustrative example for a fictional business. This document was generated by the Legal Policy Generator clause engine from invented facts about a business that does not exist. Do not copy it as-is: it describes the fictional business's practices, not yours, and it is not legal advice.

Generate your own Privacy Policy

Facts supplied for this fictional business

Application platform with accounts and user content; identity, account content, and technical usage data; transactional email through Postmark; standard product analytics through Firebase with prior consent; no advertising; recurring payments handled by the Apple App Store and Google Play; adult audience; CalOPPA and other US state modules with Do Not Track handling and no sale or sharing; international processing under standard contractual clauses; no AI features.

Privacy Policy

Privacy Policy for Example Habits

Effective date
2026-09-23

Introduction

This Privacy Policy explains how Example Apps Inc. (fictional) processes personal information in connection with Example Habits. It takes effect on 2026-09-23. It is based on the service practices described by its operator and should be read together with notices shown when information is collected.

Who operates this service

Example Apps Inc. (fictional) is the business responsible for this policy and is established in the United States, with a postal address at 100 Example Avenue, Example City.

Scope

This policy applies to the application offered under the Example Habits name. It does not govern independent third-party services that publish their own privacy terms.

Information we collect

Depending on use of the service, Example Apps Inc. (fictional) collects these broad categories: identity and contact information; account information, submitted content, and communications; and technical, usage, and device information. Specific data depends on the features used and the practices described below.

Some information is required to provide requested features; if it is not supplied, those features may be unavailable.

Sources of information

Information comes from users directly and automatic collection from the devices used to access the service. Information received from another source is handled for the purposes described in this policy and subject to applicable restrictions.

How we use information

Information is used for providing and securing the service; managing accounts, support, payments, and communications; and analytics and product improvement. It may also be used to prevent misuse, establish or defend legal claims, meet legal obligations, and enforce service terms where those activities are relevant and permitted.

Messages and email

The service sends transactional service messages using Postmark. Contact details are used for delivery, service administration, and the purposes described when the details are collected.

Transactional messages are sent only as needed to provide, secure, or administer the service. The operator does not measure message opens or link interactions.

Cookies and tracking technologies

The service uses essential storage and cookies and analytics technologies. The operator states that non-essential technologies are handled as follows: non-essential technologies start only after the user consents. Preferences can be reviewed or changed through the Privacy screen in the app settings. Browser controls may also limit storage, but blocking essential storage can prevent features from working.

Analytics

The service uses standard product analytics with Firebase to understand service operation, usage, errors, and improvements. Analytics data may include technical, device, interaction, approximate-location, and identifier information according to the selected configuration and provider controls.

Payments

Payments are processed using Apple App Store and Google Play for recurring subscriptions. The operator does not directly store full payment-card information; the payment provider handles card details under its own privacy terms. Some purchases are also handled by an app store or marketplace, which independently processes the purchase account and payment method.

Sharing and disclosures

Information may be disclosed to service providers for the purposes described in this policy, subject to contracts and legal limits where required. It may also be disclosed to authorities, courts, advisers, or transaction counterparties when reasonably necessary for law, safety, claims, or a business reorganization. Selected service providers include Firebase and Google Cloud.

The operator states that it does not sell personal information or share it for cross-context behavioral advertising as those terms are defined by applicable United States privacy laws. Ordinary disclosures to service providers, legal recipients, and user-directed recipients are not treated as a sale when statutory conditions are met.

International transfers

Information may be processed outside the United States. The stated location and safeguard approach is: standard contractual clauses.

Data retention

The retention model is: records are kept while the account or relationship remains active and for a justified period afterward. Records may be kept longer when reasonably necessary for security, disputes, tax, accounting, fraud prevention, legal obligations, or enforcement. Deletion or de-identification follows the stated model and applicable law.

Security

The operator uses encryption, access restrictions, and backups and monitoring, selected according to the nature and risk of the information. No transmission or storage method is completely secure, so absolute security cannot be guaranteed.

Children's privacy

The service is intended for adults only. If the operator learns that information was collected from a child contrary to the stated audience or applicable law, it will take reasonable steps to delete it and may ask for age or authority verification.

Your choices and privacy rights

Depending on location and processing, users may ask to access, correct, delete, restrict, or receive information; withdraw consent; unsubscribe; object; or opt out of sale, sharing, or targeted advertising. Requests are supported through the account settings or by email to privacy@example.org. The operator may verify identity and authority, apply legal exceptions, and explain a denial and available appeal where required.

United States privacy disclosures

United States privacy duties vary by state, sector, data type, and business activity. This policy describes selected factual practices and adds state-specific rights only where the operator identified those laws as applicable. It does not claim that one nationwide GDPR-equivalent framework governs every user or processing activity.

California Online Privacy Protection Act disclosures

CalOPPA has applied since July 1, 2004 and was amended in 2013 to add online-tracking disclosures. This policy identifies collected categories, information sources, recipients, review and correction methods, change notices, and its effective date. Browser Do Not Track handling: the app does not track users across third-party websites or apps, so browser Do Not Track signals do not change its behavior. Third parties collect information over time and across services only where described in the analytics, advertising, social, or service-provider sections.

Other United States state privacy rights

Several United States states have comprehensive consumer privacy laws, such as the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, and the Texas Data Privacy and Security Act. Whether one of these laws, or a similar law of another state, applies depends on the consumer's state of residence, the operator's activities, the law's thresholds, and its exemptions. This section summarizes rights and practices under those laws and does not expand or waive any statutory right.

Where such a law applies, residents may, subject to its definitions and exceptions, confirm whether their personal data is processed and access it, correct inaccuracies, delete personal data, obtain a portable copy, and opt out of processing for targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects. Requests can be submitted through the account settings or by email to privacy@example.org. The operator may need to verify the identity of the person making a request.

For these laws, the categories of personal data processed are identity and contact information; account information, submitted content, and communications; and technical, usage, and device information, and the purposes of processing are providing and securing the service; managing accounts, support, payments, and communications; and analytics and product improvement. The operator describes the personal data it shares with third parties, and the categories of those third parties, as follows: identifiers and app usage data are shared with cloud hosting and analytics providers that process them for the app; no personal data is sold.

The operator states that it does not process sensitive data as these laws define it, such as precise geolocation, health, genetic or biometric data, or data revealing racial or ethnic origin or religious beliefs.

If the operator declines to act on a request made under a state privacy law, the consumer may appeal that decision. Appeals can be submitted as follows: reply to the decision email with the word Appeal within 45 days. The operator responds to an appeal in writing within the period set by the applicable state law and explains the action taken or not taken.

If an appeal is denied, the consumer may submit a complaint to the Attorney General of the consumer's state of residence. Where the applicable law requires it, the appeal decision identifies an online mechanism, if available, or another method for contacting the Attorney General.

Account and data deletion

Users can request account and associated-data deletion through email to privacy@example.org or the account settings. Some records may remain for security, legal, tax, payment, dispute, fraud-prevention, or backup-cycle needs and will remain restricted to those purposes.

Changes to this policy

This policy may be updated to reflect service, legal, or operational changes. The current version will be posted through the service or another location communicated to users with a revised effective date. Additional notice or consent will be provided only when required by applicable law.

Contact us

Privacy questions and requests may be sent to Example Apps Inc. (fictional) at privacy@example.org or by mail to 100 Example Avenue, Example City.