Token导航 LogoToken导航TokenDH.com
研究检索需要联网github未标认证来源可访问许可证需确认审计提醒

privacy-policy隐私政策

Agent Skill

privacy-policy 用于查找、检索和筛选相关信息,适合在 Codex、Claude、Cursor、Gemini CLI 中需要根据关键词、任务场景或来源线索快速定位候选结果时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

729

周安装

31

GitHub Stars

114

下载量

255
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:privacy-policy(隐私政策)
来源仓库:https://github.com/shawnpang/startup-founder-skills
仓库路径:skills/privacy-policy
安装命令:
npx skills add https://github.com/shawnpang/startup-founder-skills --skill privacy-policy
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/shawnpang/startup-founder-skills --skill privacy-policy

简介

privacy-policy 用于查找、检索和筛选相关信息,适合在 Codex、Claude、Cursor、Gemini CLI 中需要根据关键词、任务场景或来源线索快速定位候选结果时使用。

  • 适用于研究检索类任务,可结合来源仓库、安装命令和原始 README 继续核验具体用法。
  • 通过 npx skills add 命令从 GitHub 仓库安装,支持主流 AI 宿主环境。
  • 安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。
  • 当前顶部介绍为空,需结合原始 SKILL.md 内容进一步核验功能细节和使用限制。

SKILL.md

Privacy Policy

When to Use

Activate when a founder needs to create a privacy policy for a new product launch, update an existing policy for new data practices or features, expand into a new jurisdiction (EU, California, etc.), or assess whether current data handling is properly disclosed. Also activate when the user asks about GDPR, CCPA, CPRA, or general data privacy compliance.

Context Required

  • From startup-context: product type, platform (web/mobile/API), target customer segments, geographic markets, business model, tech stack.
  • From the user: product name and URL, company legal name and address, contact email for privacy inquiries, what personal data is collected and how, which third-party services process data (analytics, payment processors, CRMs, AI providers), applicable jurisdictions, whether the product targets minors, and any existing privacy documentation.

Workflow

  1. Research the product -- Visit the product website or review the product description. Identify all data collection methods, third-party integrations, and primary features that involve personal data.
  2. Map data collection -- Categorize all data into: directly provided (forms, account creation), automatically collected (cookies, device info, usage data, IP addresses), third-party sources, and special/sensitive categories. Build a structured data inventory.
  3. Identify applicable laws -- Based on where users are located and where the company operates, determine which privacy frameworks apply: GDPR, CCPA/CPRA, state privacy laws, COPPA, industry-specific regulations. Note specific obligations per jurisdiction.
  4. Structure the policy -- Organize using the 15-section template below. Write in plain language at an 8th-grade reading level. Be specific about actual practices -- say "We collect your email address when you sign up" rather than "We may process identifiers."
  5. Flag legal review areas -- Mark sections requiring attorney review with [LEGAL REVIEW REQUIRED] notation. These include legal basis determinations, international transfer mechanisms, and jurisdiction-specific rights.
  6. Provide implementation context -- Explain why each section matters, what company decisions are needed, and what compliance considerations apply. Include a pre-publication checklist.
  7. Generate compliance summary -- Produce a separate document with data inventory table, jurisdiction applicability matrix, risk flags, and implementation checklist.

Output Format

Three-part deliverable:

Part 1: Quick Reference Summary

Product details, data types collected, applicable jurisdictions, user rights summary, retention overview, and contact information.

Part 2: Full Policy Document (15 sections)

  1. Preamble -- Who you are, what this policy covers, effective date, contact methods.
  2. Information We Collect -- Categories: personal info, usage data, device information, location, payment info, communications, sensitive data.
  3. How We Collect Information -- Methods: direct entry, automatic tracking, third parties.
  4. How We Use Information -- Purposes: service provision, support, improvements, analytics, marketing, security, legal compliance.
  5. Legal Basis for Processing -- Consent, contract performance, legal obligation, vital interests, legitimate interests (GDPR-focused).
  6. Data Sharing and Third Parties -- Service providers, partners, legal authorities, with specifics on who and why.
  7. International Data Transfer -- Cross-border transfer mechanisms (SCCs, adequacy decisions), storage locations.
  8. Data Retention -- Specific timeframes for account data, logs, deleted content.
  9. User Rights -- Access, deletion, correction, restrict processing, portability, opt-out, complaint procedures -- organized by jurisdiction.
  10. Cookies and Tracking -- Tools used, purposes, management options, consent requirements.
  11. Security -- Encryption, access controls, audits, incident response, limitations.
  12. Children's Privacy -- Parental consent, age gates, COPPA/UK Children's Code compliance.
  13. Contact and Rights Requests -- Privacy email, address, response timeframes, DPO info.
  14. Policy Changes -- Notice period, notification methods, user opt-out options.
  15. Additional Provisions -- Data sale disclosure, third-party link disclaimers, governing law, effective date.

Part 3: Compliance Notes

  • Sections flagged for legal review with rationale
  • Jurisdiction-specific considerations
  • Pre-publication checklist (see below)
  • Recommended modifications by product type

Frameworks & Best Practices

GDPR Core Requirements

  • Lawful basis required for each processing activity (Art. 6).
  • Data Protection Impact Assessment for high-risk processing (Art. 35).
  • 72-hour breach notification to supervisory authority (Art. 33).
  • Data Processing Agreements with all processors (Art. 28).
  • Right to erasure with defined exceptions (Art. 17).
  • Privacy by design and by default (Art. 25).

CCPA/CPRA Core Requirements

  • "Do Not Sell or Share My Personal Information" link required if applicable.
  • Right to know, delete, correct, and opt out of sale/sharing.
  • 12-month lookback for data collection disclosures.
  • Sensitive personal information: right to limit use (CPRA addition).
  • Service provider vs. contractor vs. third party distinctions matter.

Plain Language Principles

  • Write at an 8th-grade reading level with short sentences.
  • Use concrete examples instead of abstract categories.
  • Avoid "may" when you mean "do." Be specific about actual practices.
  • The policy must match what your product actually does -- no over-disclosure and no under-disclosure.

Pre-Publication Checklist

  • Attorney review completed
  • Policy matches actual data practices
  • User privacy request processes are accessible and functional
  • Technical security measures implemented
  • Data Processing Agreements in place with all third parties
  • Legal basis documented for each processing activity
  • Cookie consent mechanism implemented (EU users)
  • User notification system for material policy changes

Common Startup Pitfalls

  • Copying another company's privacy policy (their data practices are not yours).
  • Missing analytics and advertising SDKs in disclosures (Google Analytics, Mixpanel, Facebook Pixel all collect personal data).
  • No mechanism to actually fulfill deletion requests in the codebase.
  • Assuming B2B means no privacy obligations (you still process individual user data).
  • Listing data categories you do not actually collect (over-disclosure invites scrutiny).

Related Skills

  • terms-of-service -- Draft alongside the privacy policy; they should cross-reference each other and use consistent definitions.
  • soc2-prep -- SOC 2 Trust Service Criteria for Privacy directly overlaps with privacy policy commitments.
  • security-review -- Security measures described in the privacy policy must reflect actual technical controls.

Examples

Example 1: New SaaS product launching in US and EU

User: "We're launching our project management SaaS next month with users from the US and Europe. We use Stripe, Mixpanel, and AWS."

Good output: A three-part deliverable. The data inventory table mapping each data category to collection method, purpose, legal basis, third parties, and retention. Jurisdiction analysis identifying GDPR applicability and CCPA threshold monitoring. Red flags for Mixpanel IP collection needing disclosure and DPA, and missing cookie consent mechanism for EU users.

Example 2: Updating policy after adding AI features

User: "We added an AI assistant that processes customer messages. Do we need to update our privacy policy?"

Good output: Identifies the new data processing (message content processed by AI models), new third party (AI provider as sub-processor), new legal basis analysis needed, and GDPR Art. 22 consideration for automated decision-making. Provides the specific policy sections that need updating with draft language.


Disclaimer: This skill generates draft privacy policies and compliance guidance for educational and planning purposes only. It does not constitute legal advice. Always have a qualified attorney licensed in your relevant jurisdictions review the final privacy policy before publication. Regulatory non-compliance can result in significant fines (up to 4% of global annual revenue under GDPR).

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

35.94%
按下载量换算92

Claude

30.37%
按下载量换算77

Cursor

21.3%
按下载量换算54

Gemini CLI

9.59%
按下载量换算24

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

可疑

权限和风险

需要联网

该 Skill 可能需要联网访问来源站点、仓库或外部 API;具体网络访问范围需要结合源码和 README 复核。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills