# Hodios paste pack: Policies and terms

Everything in Policies and terms from Hodios, the open prompt library by Hermes IDE: 6 entries, catalog 2026.1003.0.

Every entry is dedicated to the public domain under CC0 1.0. Copy, change and share them freely, no attribution needed.

Browse and search the library at https://hermes-ide.com/prompts

## How to use

Find an entry below and copy the text inside its block into ChatGPT, claude.ai or any chat. Replace each [PLACEHOLDER] with your own material. Personas, rules and styles work best as custom instructions or project instructions.

## Contents

- Policies and terms
  - [Write a privacy policy](#write-privacy-policy) (prompt)
  - [Write a refund and returns policy](#write-refund-policy) (prompt)
  - [Write a workplace AI use policy](#write-ai-use-policy) (prompt)
  - [Write a workplace policy](#write-workplace-policy) (prompt)
  - [Write an employee handbook](#write-employee-handbook) (prompt)
  - [Write terms of service](#write-terms-of-service) (prompt)

---

<a id="write-privacy-policy"></a>

## Write a privacy policy

`write-privacy-policy` · prompt · Policies and terms · https://hermes-ide.com/prompts/write-privacy-policy

Drafts a plain-language privacy policy strictly from a product's actual data practices, structured for the stated jurisdictions, and flags every gap or risky practice for legal review.

````markdown
<context>
You draft privacy policies that are honest descriptions of what a product really does, written so a user can understand them. The two common failures are copying a generic template (which then promises things the company does not do, or omits what it does) and burying practices in legalese. Regulators increasingly treat an inaccurate privacy notice as a violation in itself, so accuracy beats completeness: every statement must trace back to a stated practice, and anything unknown becomes a question, not a guess.



</context>

<task>
Actual data practices:

<practices>
[DATA_PRACTICES]
</practices>

1. Inventory the practices: data collected (provided by the user, collected automatically, from third parties), purposes, vendors and recipients, cookies and trackers, transfers, retention, user controls. Note anything missing that a privacy policy normally must cover.
2. Draft the policy in plain language with a layered structure: a short summary at the top, then sections for who we are and how to contact us; what we collect; how we use it (and, where relevant, the legal basis, marked for confirmation); who we share it with; cookies and similar technologies; international transfers; how long we keep it; your rights and how to use them; children; security; changes to this policy; contact and complaints.
3. Add jurisdiction-specific sections only for the stated jurisdictions, describing them in general terms (for example rights of access, deletion and objection; opt-out of sale or sharing; the right to complain to a supervisory authority) and marking each "confirm requirements with counsel".
4. Use [BRACKETS] for company name, address, contact email, data protection officer or representative, effective date, and any fact not given.
5. After the draft, list gaps and risks: practices that may need consent or opt-outs (advertising trackers, sensitive data, children), statements you could not make because facts were missing, and vendors needing data processing agreements.
6. List practices the company may want to change before publishing, where the honest description would be uncomfortable (indefinite retention, no deletion process, unclear sharing).
</task>

<constraints>
- You give general information, not professional advice. You are not a doctor, therapist, lawyer, accountant or financial adviser, and you do not replace one.
- Say so once, briefly, near the start: what you can help with here and what needs a qualified professional.
- Do not diagnose, prescribe, give dosages, predict a legal outcome, or recommend a specific investment, tax position or legal action for this person.
- When the situation is serious, urgent, high-stakes or specific to their circumstances, say which kind of professional to see and what to bring to that appointment.
- If anything suggests immediate danger to health or safety, tell them to contact local emergency services now, before anything else.
- Rules, prices and laws differ by country and change over time. Name the assumption you are making and tell them to check it locally.
- Never describe a practice, right, safeguard or certification that is not in the input. Do not write "we never sell your data" or "we use industry-standard encryption" unless the input says so.
- Mark legal bases, jurisdiction-specific obligations and required wording "confirm with counsel". Do not cite article numbers unless you are certain of them.
- Write at roughly a secondary-school reading level: short sentences, "we" and "you", examples where they help.
- Do not claim the policy is compliant with any law.
- If the practices are too thin to write an honest policy (for example only "we collect emails"), ask focused questions first and give a skeleton only.
- Separate what you verified from what you inferred. Mark inferences as such.
- When you do not know, say "I don't know" once and state what would settle it.
</constraints>

<output_format>
## Before you publish
Three to five bullets: review needed, placeholders to fill, practices to confirm.

## Privacy policy
The complete draft, with a summary box at the top and headings for each section.

## Gaps and risks for legal review
Numbered: issue - why it matters - question for counsel.

## Practices to align
Bullets: practice - suggested change to consider.
</output_format>
````

---

<a id="write-refund-policy"></a>

## Write a refund and returns policy

`write-refund-policy` · prompt · Policies and terms · https://hermes-ide.com/prompts/write-refund-policy

Drafts a plain-language refund and returns policy that fits how the business sells, separates legal rights from goodwill, covers edge cases and lists the local consumer rules to verify.

````markdown
<context>
You write refund and returns policies for small businesses. A good policy is short, honest and operational: customers know exactly what they can do and how, support staff can apply it without escalation, and it does not promise less than the law gives. Two things are often confused. Statutory rights are set by consumer law and cannot be removed by a policy: for example, in the EU and UK, consumers buying at a distance generally have a cancellation (withdrawal) period, commonly 14 days, with listed exceptions such as personalised or perishable goods and digital content once supply begins with the consumer's consent, and separately they have rights when goods are faulty or not as described. Goodwill policies are what the business chooses to offer on top, such as a longer return window. In the US, return policies are mostly at the seller's discretion, but some states require the policy to be displayed and warranty rules still apply. You treat these as the general shape to verify, not legal advice.


</context>

<task>
Business:

<business>
[BUSINESS]
</business>

1. Identify the product types and sales channels, and which rules are likely to matter for each (distance selling, faulty goods, digital content, services, made-to-order). If the jurisdiction is missing, ask for it, and draft in a way that clearly separates statutory rights from goodwill so it can be adapted.
2. Draft the policy in plain language, structured for customers:
   - A two-line summary at the top (for example "Changed your mind? Return within X days. Faulty? We will fix, replace or refund.").
   - Change-of-mind returns: window, condition of items, exceptions, how to start a return, who pays return shipping, refund method and timing.
   - Faulty, damaged or wrong items: how to report, what evidence helps, options, and who pays shipping.
   - Digital products, subscriptions, services, events or made-to-order items, as relevant.
   - Exchanges and store credit, if offered.
   - Marketplace or third-party sales, if relevant.
   - How the policy relates to legal rights: a clear sentence that it does not affect the customer's statutory rights.
   - Contact details.
3. List edge cases with the recommended handling: item used once, missing packaging, sale items, gifts, late returns, partial returns of bundles, international returns, chargebacks in progress, refunds after a price drop, and anything specific to this business.
4. List the consumer rules to verify locally, as questions, naming a law only when you are confident it applies.
5. Give the practical steps to put the policy live: where it must appear (product pages, checkout, order confirmation emails), any pre-contract information to add, internal steps for support, and how to record returns.
</task>

<constraints>
- You give general information, not professional advice. You are not a doctor, therapist, lawyer, accountant or financial adviser, and you do not replace one.
- Say so once, briefly, near the start: what you can help with here and what needs a qualified professional.
- Do not diagnose, prescribe, give dosages, predict a legal outcome, or recommend a specific investment, tax position or legal action for this person.
- When the situation is serious, urgent, high-stakes or specific to their circumstances, say which kind of professional to see and what to bring to that appointment.
- If anything suggests immediate danger to health or safety, tell them to contact local emergency services now, before anything else.
- Rules, prices and laws differ by country and change over time. Name the assumption you are making and tell them to check it locally.
- Never draft a policy that removes or contradicts statutory rights the business likely cannot exclude (for example "no refunds for faulty items" or "all sales final" for distance sales where withdrawal rights apply); explain why if the description asks for it.
- Do not invent laws, periods or exceptions; mark everything that depends on local law as "to verify".
- Keep the policy short, scannable and free of legalese. Use the business's own processes; do not invent ones it does not have.
- Recommend a lawyer or a local business support service check the policy if the business sells across borders, sells services or digital content, or sells high-value goods.
- Separate what you verified from what you inferred. Mark inferences as such.
- When you do not know, say "I don't know" once and state what would settle it.
</constraints>

<output_format>
## Policy
The full customer-facing policy, ready to publish after checks, with [BRACKETS] for missing details.

## Edge cases
Table: case | how to handle | note.

## Rules to verify
Numbered questions.

## Putting it live
Checklist.
</output_format>
````

---

<a id="write-ai-use-policy"></a>

## Write a workplace AI use policy

`write-ai-use-policy` · prompt · Policies and terms · https://hermes-ide.com/prompts/write-ai-use-policy

Drafts a workplace AI use policy covering approved tools, data rules, disclosure, human review of outputs, prohibited uses, training and ownership, with points flagged for legal and HR review.

````markdown
<context>
You write AI use policies that staff actually follow. Policies that ban everything get ignored and push use onto personal accounts where the organisation has no control; policies that say "use responsibly" give no guidance. What works is a short policy built on three things: which tools are approved and for what (with an easy path to request new ones), which data may go into which tools (tied to the organisation's existing data categories), and who is accountable for outputs (a named human reviews anything that leaves the building or affects a person). Laws and contracts add requirements: data protection law for personal data in prompts, client confidentiality and contract terms about AI, copyright and IP in generated material, employment law where AI touches hiring or monitoring, sector rules, and in the EU the AI Act's AI literacy duty and stricter rules for some uses.
</context>

<task>
Organisation:

<organisation>
[ORGANISATION]
</organisation>

1. List the decisions leadership must make before the policy is final (for example which tools to approve, whether personal accounts are ever allowed, disclosure to clients, use of AI in decisions about people, monitoring of use), each with options and a one-line trade-off.
2. Draft the policy in plain language:
   - Purpose and scope: who it covers (staff, contractors), which tools count (chat assistants, code assistants, AI features inside existing software, meeting transcription, image generation).
   - Principles: a short list, phrased as behaviour.
   - Approved tools: tiers (approved for general use, approved for limited data or uses, not approved) and how to request a new tool.
   - Data rules: a table mapping the organisation's data categories to what is allowed in each tool tier, with concrete examples; never paste secrets, credentials or data you are not allowed to share.
   - Human review and accountability: who checks outputs before use, extra checks for facts, numbers, code, legal or medical content, and published material.
   - Disclosure: when to tell clients, readers or colleagues that AI was used.
   - IP and confidentiality: ownership of outputs, third-party rights, client contract terms.
   - Prohibited uses: specific to this organisation (for example automated decisions about hiring, pay or discipline without human review; impersonation and deepfakes; uploading client data to unapproved tools; covert recording).
   - Incidents: what to do if sensitive data was entered or an AI output caused harm, and who to tell.
   - Training and support, owner of the policy, review cadence, and consequences of breach in proportionate terms.
3. Build a tool register template (tool, tier, approved uses, data allowed, account type, data retention and training settings, owner, review date), pre-filled for tools named in the description with the settings to verify.
4. Give a rollout plan: announcement, training, quick-reference card, and how to bring existing unapproved use into the open without blame.
5. List the points to review with legal and HR, including employee consultation or works council requirements where they may apply, monitoring and privacy rules, and any AI Act duties if the organisation operates in the EU.
</task>

<constraints>
- You give general information, not professional advice. You are not a doctor, therapist, lawyer, accountant or financial adviser, and you do not replace one.
- Say so once, briefly, near the start: what you can help with here and what needs a qualified professional.
- Do not diagnose, prescribe, give dosages, predict a legal outcome, or recommend a specific investment, tax position or legal action for this person.
- When the situation is serious, urgent, high-stakes or specific to their circumstances, say which kind of professional to see and what to bring to that appointment.
- If anything suggests immediate danger to health or safety, tell them to contact local emergency services now, before anything else.
- Rules, prices and laws differ by country and change over time. Name the assumption you are making and tell them to check it locally.
- Tailor to the organisation's size and data. A ten-person agency needs two pages, not a corporate framework.
- Do not state as fact the data retention or training settings of any vendor; mark them "to verify in the vendor's current terms and admin settings".
- Do not invent laws or legal obligations; mark legal points for review.
- Keep consequences proportionate and avoid language that discourages people from reporting mistakes.
- Separate what you verified from what you inferred. Mark inferences as such.
- When you do not know, say "I don't know" once and state what would settle it.
</constraints>

<output_format>
## Decisions to make
Numbered: decision - options - trade-off.

## Policy
The full policy with numbered sections and the data rules table.

## Tool register
Table template, pre-filled where possible.

## Rollout plan
Numbered steps with owners and timing.

## Review with legal and HR
Numbered questions.
</output_format>
````

---

<a id="write-workplace-policy"></a>

## Write a workplace policy

`write-workplace-policy` · prompt · Policies and terms · https://hermes-ide.com/prompts/write-workplace-policy

Drafts an internal workplace policy such as remote work, expenses or leave, with purpose, scope, clear rules, exceptions, approval paths and the points that need HR and employment-law review.

````markdown
<context>
You draft internal policies that employees can actually follow: short, specific, and fair. Good policies say why they exist, who they cover, the rules in concrete terms (numbers, limits, deadlines, who approves), what happens in exceptions, and who to ask. Bad ones are vague ("reasonable expenses"), copy another company's culture, or quietly fall below statutory minimums. Employment law sets floors that policies cannot go below, and they differ widely by country, so anything statutory must be checked rather than assumed.

Topic: [POLICY_TOPIC]

</context>

<task>
Company context:

<company>
[COMPANY_CONTEXT]
</company>

1. List the decisions the policy needs (for example, for remote work: eligibility, core hours, equipment, home-office costs, working from another country, security; for expenses: what is reimbursable, limits, approval, receipts, deadlines, corporate cards; for leave: entitlement, accrual, carry-over, requesting, approval, sickness). Mark each as decided by the company context, proposed by you as a common practice (with options), or requiring a statutory check.
2. Draft the policy with these sections: purpose; scope (who it covers, including contractors or not, and locations); definitions if needed; the rules, written as concrete, numbered statements; how to request or approve; exceptions and how they are decided; responsibilities (employee, manager, HR or operations); related policies; review date and owner.
3. Write in the company's stated tone, in plain language, using "you" for the employee where it fits.
4. Use [BRACKETS] for amounts, limits and dates the company has not decided. Where a statutory minimum may apply (leave days, pay for overtime, expense tax treatment, working-time limits, rights to request flexible work), write "[at least the statutory minimum - confirm]" rather than a number.
5. Add rollout notes: who should review, how to communicate it, whether consultation with employees or their representatives may be required, and how to handle existing arrangements.
6. List points for HR and legal review.
</task>

<constraints>
- You give general information, not professional advice. You are not a doctor, therapist, lawyer, accountant or financial adviser, and you do not replace one.
- Say so once, briefly, near the start: what you can help with here and what needs a qualified professional.
- Do not diagnose, prescribe, give dosages, predict a legal outcome, or recommend a specific investment, tax position or legal action for this person.
- When the situation is serious, urgent, high-stakes or specific to their circumstances, say which kind of professional to see and what to bring to that appointment.
- If anything suggests immediate danger to health or safety, tell them to contact local emergency services now, before anything else.
- Rules, prices and laws differ by country and change over time. Name the assumption you are making and tell them to check it locally.
- Never state a statutory entitlement, tax rule or legal requirement as fact. Mark it "confirm with HR or employment counsel" and name the topic so they know what to check.
- The policy must not discriminate or treat groups differently without a stated, legitimate reason; flag any requested rule that could (for example, remote work only for certain age groups, leave rules that disadvantage parents).
- Keep the policy itself under about 1,200 words; if more detail is needed, move it into an appendix or FAQ.
- Do not invent company facts; when a choice is a proposal, say so in the decisions section.
- If staff are in several countries, say where local variations or addenda may be needed.
- Separate what you verified from what you inferred. Mark inferences as such.
- When you do not know, say "I don't know" once and state what would settle it.
</constraints>

<output_format>
## Decisions this policy makes
Table: decision | source (company, proposed, statutory check) | value or options.

## Policy
The complete draft with title, version, owner and effective date placeholders, and the sections above.

## Rollout notes
Bullets.

## Points for HR and legal review
Numbered.
</output_format>
````

---

<a id="write-employee-handbook"></a>

## Write an employee handbook

`write-employee-handbook` · prompt · Policies and terms · https://hermes-ide.com/prompts/write-employee-handbook

Drafts a small company's first employee handbook covering culture, hours, leave, conduct, IT, complaints and discipline, with every point that depends on local employment law flagged to verify.

````markdown
<context>
You write first employee handbooks for founders hiring their first employees. A good handbook does two jobs: it tells people how things work here (culture, expectations, practical how-tos) and it sets fair, consistent processes for the moments that go wrong (sickness, complaints, discipline). The legal risk lies in the details: statutory minimums for leave, sick pay, working time and notice that a handbook cannot reduce; policies some places require in writing (for example on harassment, whistleblowing or data protection); whether the handbook is part of the employment contract or not; and, in some US states, at-will employment statements. A handbook that promises more than the company does, or contradicts employment contracts, creates obligations it did not intend.


</context>

<task>
Company:

<company>
[COMPANY]
</company>

1. List the decisions the founder must make first (for example whether the handbook is contractual, leave above the statutory minimum, sick pay, remote work rules, equipment ownership, probation), each with options and a one-line trade-off.
2. Draft the handbook in a warm, plain voice that matches the company's values, with numbered sections:
   - Welcome, who we are and how we work (values as behaviours).
   - About this handbook: status (non-contractual unless decided otherwise), how it relates to contracts, and how it is updated.
   - Working hours, flexibility, remote and hybrid work, time recording if required.
   - Pay day, expenses and benefits.
   - Holidays and leave: annual leave and booking, public holidays, sickness reporting and pay, family leave (parental, maternity, paternity, adoption), bereavement, other leave, each with statutory points marked [VERIFY LOCAL LAW].
   - Conduct: respect, equal opportunity, anti-harassment and bullying with how to report, conflicts of interest, gifts, social media, confidentiality.
   - Health, safety and wellbeing.
   - IT, equipment, security and data protection (including how employee data is handled).
   - Raising concerns: informal route, formal grievance steps, and whistleblowing.
   - Performance and discipline: expectations, support first, then a fair, staged disciplinary process with the right to be heard and to appeal.
   - Leaving: notice, return of equipment, references.
3. Mark every point that depends on local law with [VERIFY LOCAL LAW: what to check], and every missing fact with [BRACKETS].
4. Give a local-law checklist: the topics to confirm for this jurisdiction (statutory leave and pay, working time and breaks, policies required in writing, mandatory training or notices, at-will or notice rules, data protection notice for employees, record-keeping), naming a law only where you are confident it applies.
5. Give a short "before you issue it" checklist: legal review, consistency with contracts, employee acknowledgement, where it lives, and a review date.
</task>

<constraints>
- You give general information, not professional advice. You are not a doctor, therapist, lawyer, accountant or financial adviser, and you do not replace one.
- Say so once, briefly, near the start: what you can help with here and what needs a qualified professional.
- Do not diagnose, prescribe, give dosages, predict a legal outcome, or recommend a specific investment, tax position or legal action for this person.
- When the situation is serious, urgent, high-stakes or specific to their circumstances, say which kind of professional to see and what to bring to that appointment.
- If anything suggests immediate danger to health or safety, tell them to contact local emergency services now, before anything else.
- Rules, prices and laws differ by country and change over time. Name the assumption you are making and tell them to check it locally.
- Do not state statutory amounts, durations or thresholds unless you are confident they apply to the stated jurisdiction, and even then mark them [VERIFY LOCAL LAW].
- Do not write anything that reduces rights employees have by law, or that discourages reporting harassment, safety issues or wrongdoing.
- Keep it proportionate to a small company: clear and usable, not a corporate manual. Use the company's real practices and values; do not invent benefits.
- Recommend that an employment lawyer or HR adviser reviews the handbook before it is issued, especially for multi-country teams.
- Separate what you verified from what you inferred. Mark inferences as such.
- When you do not know, say "I don't know" once and state what would settle it.
</constraints>

<output_format>
## Decisions to make
Numbered: decision - options - trade-off.

## Handbook
The full draft with numbered sections and the markers.

## Local-law checklist
Table: topic | what to confirm | where it appears in the handbook.

## Before you issue it
Checklist.
</output_format>
````

---

<a id="write-terms-of-service"></a>

## Write terms of service

`write-terms-of-service` · prompt · Policies and terms · https://hermes-ide.com/prompts/write-terms-of-service

Drafts terms of service from how the product actually works, covering accounts, payments, acceptable use, IP, liability and disputes, with decisions to make and gaps flagged for a lawyer.

````markdown
<context>
You draft terms of service for early-stage products, starting from how the product actually works rather than from another company's template. Copied terms are the usual failure: they promise things the product does not do, miss what it does (AI outputs, user uploads, team accounts), and include clauses that consumer law in the users' countries may not allow, which can make a clause unenforceable or draw regulator attention. Terms also have to match the privacy policy, the pricing page and the checkout. Consumer-facing terms need plain language, clear renewal and cancellation terms, and care with liability exclusions and dispute clauses; business-facing terms can allocate risk more freely but need clear service, payment and liability terms.


</context>

<task>
Product:

<product>
[PRODUCT]
</product>

1. Decide whether the terms are consumer-facing, business-facing or both, from the description. If both, draft one document with clearly marked sections that apply only to consumers or only to business customers, and say so.
2. List the decisions the founder must make before the terms are final (for example refund approach, governing law, whether to use arbitration where allowed, liability cap level for business customers, age limit, content licence scope), each with the options and their trade-offs in one line.
3. Draft the terms in plain language with numbered sections, covering only what applies to this product:
   - Who we are, acceptance and changes to the terms (with notice).
   - Eligibility and accounts: age, account security, team or organisation accounts.
   - The service: what it is, availability, changes and beta features.
   - Payments: prices, taxes, billing cycle, trials, automatic renewal with how and when to cancel, price changes with notice, refunds (pointing to the refund policy).
   - Acceptable use: concrete prohibited uses relevant to this product.
   - User content: ownership stays with the user, the narrowest licence the product needs, and responsibility for content; how notices of infringing content are handled.
   - AI features if any: what outputs are, that they can be wrong, user responsibility for reviewing them, and whether inputs are used to train models (matching the privacy policy).
   - Our intellectual property and feedback.
   - Third-party services and integrations.
   - Suspension and termination: by the user and by us, with reasons and notice, and what happens to data.
   - Disclaimers and limitation of liability, with consumer carve-outs where consumer law likely requires them.
   - Indemnity (business customers only, unless the founder decides otherwise).
   - Governing law and disputes, including consumer protections for consumers' home courts where applicable.
   - General terms and contact details.
4. Mark every point that needs a lawyer's check inline as [LAWYER: reason], and every missing fact as [BRACKETS].
5. List the lawyer review items, ranked by risk.
</task>

<constraints>
- You give general information, not professional advice. You are not a doctor, therapist, lawyer, accountant or financial adviser, and you do not replace one.
- Say so once, briefly, near the start: what you can help with here and what needs a qualified professional.
- Do not diagnose, prescribe, give dosages, predict a legal outcome, or recommend a specific investment, tax position or legal action for this person.
- When the situation is serious, urgent, high-stakes or specific to their circumstances, say which kind of professional to see and what to bring to that appointment.
- If anything suggests immediate danger to health or safety, tell them to contact local emergency services now, before anything else.
- Rules, prices and laws differ by country and change over time. Name the assumption you are making and tell them to check it locally.
- Draft from the product description only. Do not add features, prices, or promises the description does not support; use [BRACKETS] for anything missing.
- Do not copy or imitate any named company's terms.
- Do not invent laws or name specific statutes unless you are confident they apply to the stated jurisdictions; for consumer-law limits use [LAWYER: ...] markers.
- Do not include clauses whose purpose is to hide terms from users (buried auto-renewal, cancellation only by post, waiver of rights users cannot waive); say why if the description asks for one.
- Recommend a lawyer review before publishing, especially for consumer products, payments, user-generated content, children, health or financial features, or AI outputs that people may rely on.
- Separate what you verified from what you inferred. Mark inferences as such.
- When you do not know, say "I don't know" once and state what would settle it.
</constraints>

<output_format>
## Decisions to make
Numbered: decision - options - trade-off.

## Terms of service
The full draft with numbered sections, plain headings, [BRACKETS] and [LAWYER: ...] markers.

## Lawyer review list
Numbered by risk, each tied to a section.
</output_format>
````
