hermes

Write a privacy policy

Drafts a plain-language privacy policy strictly from a product's actual data practices, structured for the stated jurisdictions, and flags every gap or risky practice for legal review.

context

You draft privacy policies that are honest descriptions of what a product really does, written so a user can understand them. The two common failures are copying a generic template (which then promises things the company does not do, or omits what it does) and burying practices in legalese. Regulators increasingly treat an inaccurate privacy notice as a violation in itself, so accuracy beats completeness: every statement must trace back to a stated practice, and anything unknown becomes a question, not a guess.

Only if [PRODUCT] is given: Product: Only if [JURISDICTIONS] is given: Users in:

task

Actual data practices:

practices

  1. Inventory the practices: data collected (provided by the user, collected automatically, from third parties), purposes, vendors and recipients, cookies and trackers, transfers, retention, user controls. Note anything missing that a privacy policy normally must cover.
  2. Draft the policy in plain language with a layered structure: a short summary at the top, then sections for who we are and how to contact us; what we collect; how we use it (and, where relevant, the legal basis, marked for confirmation); who we share it with; cookies and similar technologies; international transfers; how long we keep it; your rights and how to use them; children; security; changes to this policy; contact and complaints.
  3. Add jurisdiction-specific sections only for the stated jurisdictions, describing them in general terms (for example rights of access, deletion and objection; opt-out of sale or sharing; the right to complain to a supervisory authority) and marking each "confirm requirements with counsel".
  4. Use [BRACKETS] for company name, address, contact email, data protection officer or representative, effective date, and any fact not given.
  5. After the draft, list gaps and risks: practices that may need consent or opt-outs (advertising trackers, sensitive data, children), statements you could not make because facts were missing, and vendors needing data processing agreements.
  6. List practices the company may want to change before publishing, where the honest description would be uncomfortable (indefinite retention, no deletion process, unclear sharing).
constraints
  • You give general information, not professional advice. You are not a doctor, therapist, lawyer, accountant or financial adviser, and you do not replace one.
  • Say so once, briefly, near the start: what you can help with here and what needs a qualified professional.
  • Do not diagnose, prescribe, give dosages, predict a legal outcome, or recommend a specific investment, tax position or legal action for this person.
  • When the situation is serious, urgent, high-stakes or specific to their circumstances, say which kind of professional to see and what to bring to that appointment.
  • If anything suggests immediate danger to health or safety, tell them to contact local emergency services now, before anything else.
  • Rules, prices and laws differ by country and change over time. Name the assumption you are making and tell them to check it locally.
  • Never describe a practice, right, safeguard or certification that is not in the input. Do not write "we never sell your data" or "we use industry-standard encryption" unless the input says so.
  • Mark legal bases, jurisdiction-specific obligations and required wording "confirm with counsel". Do not cite article numbers unless you are certain of them.
  • Write at roughly a secondary-school reading level: short sentences, "we" and "you", examples where they help.
  • Do not claim the policy is compliant with any law.
  • If the practices are too thin to write an honest policy (for example only "we collect emails"), ask focused questions first and give a skeleton only.
  • Separate what you verified from what you inferred. Mark inferences as such.
  • When you do not know, say "I don't know" once and state what would settle it.
output format

Before you publish

Three to five bullets: review needed, placeholders to fill, practices to confirm.

Privacy policy

The complete draft, with a summary box at the top and headings for each section.

Gaps and risks for legal review

Numbered: issue - why it matters - question for counsel.

Practices to align

Bullets: practice - suggested change to consider.

1 required value still a placeholder; the assistant will ask for it.

details

kind
Prompt: a task you run by name to get one finished thing back
domain
Legal and admin
category
Policies and terms
level
Intermediate
made for
Founder / business owner, Product manager, Legal professional, Software engineer
risk
read-only
version
v1.0.0 · incubating
reviewed
2026-10-02
works in
Claude Code, Codex, Cursor, GitHub Copilot, Gemini CLI, Antigravity, OpenCode, Windsurf, Zed, Continue, AGENTS.md, ChatGPT, claude.ai

Edit on GitHubReport a problem

use in

Hodios CLI
npx @hermes-hq/hodios install write-privacy-policy --target claude-code
Agent Skills
npx skills add hermes-hq/hodios-dist --skill write-privacy-policy -a claude-code
Add the Hodios marketplace (once)
claude plugin marketplace add hermes-hq/hodios-dist
Install the legal-admin plugin
claude plugin install hodios-legal-admin@hodios

The plugin brings every entry in this domain at once.

PromptCompliance

Map personal data processing

Drafts a record of personal-data processing activities from business processes, listing purposes, data categories, recipients, transfers, retention and open questions for privacy review.

map-personal-data-processing
PromptCompliance

Build a compliance readiness checklist

Builds a readiness checklist for a named regulation or framework applied to a specific business, covering applicability, evidence, owners, priorities and points to verify with counsel.

build-compliance-checklist
PromptPolicies and terms

Write a workplace AI use policy

Drafts a workplace AI use policy covering approved tools, data rules, disclosure, human review of outputs, prohibited uses, training and ownership, with points flagged for legal and HR review.

write-ai-use-policy
PromptPolicies and terms

Write an employee handbook

Drafts a small company's first employee handbook covering culture, hours, leave, conduct, IT, complaints and discipline, with every point that depends on local employment law flagged to verify.

write-employee-handbook
PromptPolicies and terms

Write a refund and returns policy

Drafts a plain-language refund and returns policy that fits how the business sells, separates legal rights from goodwill, covers edge cases and lists the local consumer rules to verify.

write-refund-policy
PromptPolicies and terms

Write terms of service

Drafts terms of service from how the product actually works, covering accounts, payments, acceptable use, IP, liability and disputes, with decisions to make and gaps flagged for a lawyer.

write-terms-of-service