Daykeeper logodaykeeper

Stripe and Apple both check for a privacy policy. Here's yours, plus terms and refunds.

Answer the questions below and you'll get a privacy policy, terms of service and refund policy filled in with your app's name, tools and refund window. Sell in the EU or UK and we add the GDPR items and the 14-day right to withdraw for you.

Your business

Optional. Leave it blank and we use your app name.
Your country, plus your state if you're in the US. This is also the law your terms follow.

What you sell

Product
Billing
0 if you don't offer one.
Refund window

Who buys from you

Adds the GDPR items and the 14-day right to withdraw.

Your setup

Tools you useEach one gets listed in your privacy policy with what it does.
What you collect

Privacy Policy

Last updated: October 1, 2026

This policy explains what personal data [Your app] collects, why we collect it, who we share it with and what you can do about it. It covers [yourapp.com] and the [Your app] service. "We", "us" and "our" mean [Your app].

Who we are

[Your app] is based in [your country or state]. For the EU and UK General Data Protection Regulation (GDPR), [Your app] is the controller of your personal data. You can reach us about anything in this policy at [support@yourapp.com].

What we collect

  • Account details: your name and email address, and your password if you sign up with one (we store it hashed).
  • Payment details: Stripe handles your card. We don't see or store your full card number. We get things like your billing name, country, the last four digits of your card and your payment history.
  • Messages you send us: anything you write to us when you ask for help or give feedback.
  • Content you create: whatever you write, upload or store in [Your app].
  • Usage data: the pages and features you use, your device and browser type, and your approximate location based on your IP address.
  • Cookies: small files that keep you signed in and, if you agree, help us measure how the site is used.
  • Technical logs: IP address, timestamps and error reports, which we need to keep the service secure and working.

How we use it and our legal basis

Under the GDPR we need a legal basis for each way we use your data. Here's each use and the basis we rely on.

  • To create your account and run [Your app] for you. Legal basis: Contract: we need it to provide what you signed up for.
  • To take payments, send receipts and keep tax and accounting records. Legal basis: Contract, and legal obligation for tax and accounting records.
  • To reply when you contact support. Legal basis: Contract, and our legitimate interest in helping our customers.
  • To keep the service secure, prevent fraud and fix bugs. Legal basis: Legitimate interests: keeping our product safe and working.
  • To send emails about your account, billing and important changes. Legal basis: Contract, and legitimate interests for service updates.
  • To send product news and tips, if you opt in. Legal basis: Consent, which you can withdraw any time by unsubscribing.
  • To understand how people use the product and make it better. Legal basis: Legitimate interests in improving our product, or consent where the law requires it for cookies.

Our legitimate interests

Where we rely on legitimate interests, those interests are keeping our service secure and preventing fraud and abuse, fixing bugs and making the product better, answering questions and helping customers and understanding which features people use. We only do this where our interests aren't outweighed by your rights. You can object at any time (see "Your rights").

Who we share it with

We don't sell your personal data. We share it only with companies that help us run [Your app], and only what they need to do their job:

  • Stripe: processes card payments and stores payment details
  • PostHog: product analytics, so we can see which features people use
  • Vercel: hosts our website and app
  • Supabase: database, file storage and sign-in
  • Resend: sends account and transactional emails
  • Daykeeper: customer support inbox and support chat

We may also share data if the law requires it, to protect our rights or users, or as part of a sale or merger of our business (you'd be told first).

International transfers

Some of these providers store or process data outside the European Economic Area and the UK, including in the United States. When we transfer personal data out of the EEA or UK, we rely on an adequacy decision for that country or on the European Commission's Standard Contractual Clauses (and the UK's equivalent). You can ask us for a copy of the safeguards we use by emailing [support@yourapp.com].

How long we keep it

  • Account data: for as long as your account is open, then deleted within 90 days of closing it.
  • Payment and invoice records: as long as tax and accounting law requires (often 6 to 10 years).
  • Support messages: for as long as they help us support you, and no longer than 3 years after your last message.
  • Usage analytics: up to 24 months, and then deleted or anonymized.
  • Backups and logs: overwritten on a rolling basis, usually within 30 to 90 days.

Your rights

If you're in the EU or UK, you have the right to:

  • access the personal data we hold about you and get a copy
  • rectification, so we fix anything that's wrong
  • erasure, so we delete your data
  • restriction, so we limit how we use it
  • object to us using it based on legitimate interests, or for direct marketing
  • portability, so you get your data in a machine-readable format
  • withdraw consent at any time where we rely on consent, without affecting what we did before
  • complain to a supervisory authority, such as the data protection authority where you live or work, or the UK Information Commissioner's Office

To use any of these rights, email [support@yourapp.com]. We'll reply within one month.

If you live outside the EU and UK, you can still ask us to access, correct or delete your data the same way. Some US states and other countries give you more rights, and we'll honor them.

Do you have to give us your data?

You need to give us your email address and payment details to create an account and pay, because we can't provide [Your app] without them. Everything else is optional. If you don't share it, some features may not work.

Automated decision-making

We don't make decisions about you based solely on automated processing, including profiling.

Cookies

We use cookies that are needed to sign you in and keep the site working. We also use analytics cookies to see how the site is used. Where the law requires it, we only set non-essential cookies after you agree, and you can change your choice at any time. You can also block or delete cookies in your browser settings.

Do Not Track

Some browsers send a "Do Not Track" signal. There's no common standard for it, so we don't respond to it right now.

Children

[Your app] isn't meant for children. We don't knowingly collect data from anyone under 13 (or under 16 in the EU and UK, unless a parent agrees). If you think a child has given us data, email [support@yourapp.com] and we'll delete it.

Security

We use encryption in transit, access controls and trusted providers to protect your data. No system is perfectly secure, so if we ever have a breach that affects you, we'll tell you and the authorities as the law requires.

Changes to this policy

If we make important changes, we'll email you or show a notice in [Your app] before they take effect. The date at the top shows when this policy last changed.

Contact

Questions about your data? Email [support@yourapp.com]. [Your app], [your country or state].

These are templates, not legal advice. Read them, change anything that doesn't match how your business works, and ask a lawyer if you handle sensitive data or sell to big companies.

What Acme Notes gets

Acme Notes is a $9 a month notes app with a 7-day trial and a 14-day refund window. It sells worldwide, takes payments with Stripe and answers support with Daykeeper. Here's part of what the generator writes for it.

Who we share it with

We don't sell your personal data. We share it only with companies that help us run Acme Notes, and only what they need to do their job:

  • Stripe: processes card payments and stores payment details
  • PostHog: product analytics, so we can see which features people use
  • Vercel: hosts our website and app
  • Supabase: database, file storage and sign-in
  • Resend: sends account and transactional emails
  • Daykeeper: customer support inbox and support chat
  • OpenAI: powers the AI features in our product

We may also share data if the law requires it, to protect our rights or users, or as part of a sale or merger of our business (you'd be told first).

Refunds

If Acme Notes isn't right for you, ask for a refund within 14 days of your first payment and we'll refund it in full. The same 14-day window applies to each yearly renewal. After that, payments aren't refundable, but you can cancel any time so you're not charged again.

We'll also refund you if we charged you by mistake, for example a double charge, or if a serious problem on our side stopped you from using Acme Notes and we couldn't fix it.

How to ask for a refund

To ask for a refund, message us from the support chat in Acme Notes, or email support@acmenotes.app. Tell us the email on your account and roughly when you paid. We'll reply within 2 business days, and approved refunds go back to your original payment method. Your bank may take 5 to 10 business days to show it.

What's in each policy

  • Every sentence comes from a fixed template. Nothing is sent to a server or an AI, and your answers stay in your browser.
  • Tick EU/UK buyers and the privacy policy adds every GDPR Article 13 item: who the controller is, the legal basis for each use, legitimate interests, who gets the data, transfers outside the EU, how long you keep it, all eight rights, whether giving data is required and automated decisions.
  • The refund policy adds the EU and UK 14-day right of withdrawal, the express-consent rule for digital services that start right away, and the online withdrawal function EU law has required since June 19, 2026.
  • Pick a mobile app and the refund policy explains that Apple handles App Store refunds and Google Play purchases follow Google's refund policies.
  • Each tool you tick shows up in the privacy policy by name, with one line on what it does with your users' data.

These are templates, not legal advice. Read them, change anything that doesn't match how your business works, and ask a lawyer if you handle sensitive data or sell to big companies.

Questions founders ask

Do I need a privacy policy for my app?

Yes, if you collect even an email address. California's CalOPPA requires a posted privacy policy on any site or app that collects personal data from Californians, and the GDPR requires one for EU and UK users. Apple won't publish an app without a privacy policy link, and Stripe's website checklist asks for a privacy policy plus your refund and cancellation policies.

Does CCPA apply to a small SaaS?

Usually not. The CCPA kicks in only if you make more than $26,625,000 a year, buy, sell or share data on 100,000 or more California consumers or households, or make half your revenue from selling or sharing personal data. CalOPPA still applies, so you need a posted privacy policy either way.

Do I have to offer refunds in the EU?

EU and UK consumers get 14 days to withdraw from an online purchase without a reason. For a subscription that starts right away, you can charge for the days they used, and for digital content they lose the right once access starts if they expressly agreed to that at checkout. Since June 19, 2026, EU law also requires an online withdrawal function, a button customers can use to withdraw.

Can I copy another company's privacy policy?

No. It's copyrighted, and it describes their tools, their data and their legal entity. A policy that lists the wrong processors or rights is a problem the day a user or regulator asks what you do with their data.

Do I legally have to make cancelling easy?

In the US, yes. The FTC's click-to-cancel rule was struck down by a federal appeals court in July 2025, but ROSCA still requires clear terms before you take card details, the customer's express consent, and a simple way to stop recurring charges. A cancel button in your billing settings covers it.

Where should my refund policy say customers can reach me?

Put one support email or support chat in it, and make sure someone reads it. Customers who can't reach you go to their bank, and a chargeback costs you a $15 fee on Stripe even when you win.

Got customers asking questions? Answer them in one place.

Daykeeper gives your app a support chat widget and one inbox for every customer message. Free for 100 conversations a month. Your AI can set it up for you in one prompt.

Start free

More free tools