All articles
Workflow

Our Privacy Policy Was Three Years Out of Date. We Fixed It Section by Section for $650, Not $2,800

PA
PromptDock AIVerified creator — vouched by Prompt Dock
Jun 22, 2026 · 8 min read
promptdock.ai/blog

Somewhere over eighteen months we added product analytics, swapped cookie providers, and wired in a third-party CRM. What we did not add, at any point, was a single edit to our privacy policy. By the time someone actually read it — me, on a slow Thursday — our three-page policy was describing a company that no longer existed. It listed practices we'd dropped and was completely silent on half of what we actually did. That's not just sloppy; in a few places it was arguably misleading, which is the kind of thing regulators and class-action lawyers find absolutely delightful.

So I asked our law firm for a full redraft. The quote came back at $2,800. For a seven-person company, that's a real number, and it happened to land in the same week as a hosting renewal and a payroll run. I did not have $2,800 of spare budget for a document that maybe 2% of our users would ever open. So I went looking for a way to get the lawyer's actual judgment without paying the lawyer to type the boilerplate parts.

Why I drafted section by section, and why Gemini

A privacy policy isn't one document — it's a stack of independent sections, each describing one data flow. That structure is perfect for a per-section prompt, because you can do them one at a time and actually keep the details straight. I used the Privacy Policy Section Generator with Reviewer Notes prompt with Gemini 3 Pro Preview, specifically because the prompt asks for a structured Markdown 'Data inventory' table for each section, and Gemini is genuinely excellent at producing clean, consistent tables and synthesizing the messy details I fed it into tidy rows. For each section I described what we collected, why, the legal basis, which vendor touched it, and the retention period. Out came a plain-language section, a data-inventory table, and a reviewer-notes block, every time, in the same shape.

Doing it as a table forced a discipline I didn't know we were missing. Filling in 'Legal basis' for every single data element meant I had to actually know our legal basis for every single data element. Twice I had to stop and go ask an engineer what a tool was really collecting, because I genuinely wasn't sure. That's not a flaw in the prompt — that's the prompt doing its job and surfacing a gap in our own knowledge before a regulator did.

The reviewer-notes block is the actual product

Here's the trick that turned a $2,800 job into a $650 one. The prompt ends every section with a 'Notes for your legal reviewer' list — every claim that depends on a technical detail we needed to confirm, and every spot where the law gets complicated. When I assembled all seven sections and sent them to our attorney, she wasn't writing from a blank page. She was reviewing a near-complete draft with a built-in to-do list pointing her straight at the two sections that actually needed her brain: the cross-border-transfer language for GDPR, and a California subsection that needed CCPA-specific rights spelled out properly.

The most underrated rule in the prompt

The single most valuable instruction is 'clearly separate what YOU do from what THIRD PARTIES do on your behalf.' Our old policy smushed those together, which is both a compliance problem and a plain clarity problem. The new sections are explicit: here's what we collect directly, here's what Mixpanel collects on our behalf and what they actually do with it, and here's what you can do about each one. That separation is legally meaningful and, as a bonus, it's the first version of our policy that a normal human could read and actually understand.

I'm not telling you to skip the lawyer — we didn't, and you absolutely shouldn't. I'm telling you to stop paying the lawyer to draft the parts a structured prompt can draft, so their expensive time goes to the parts only they can do. Grab the Privacy Policy Section Generator with Reviewer Notes prompt on Prompt Dock and rebuild your stale policy one data flow at a time, then hand the flagged draft to a human. When the inbound is a user actually exercising those rights rather than us publishing them, I pair this with my GDPR Data Subject Request Response Pack prompt to handle the request itself.

The prompt behind this post
Free
Privacy Policy Section Generator with Reviewer Notes

Describe your data practices for one area (cookies, analytics, third-party sharing, user rights) and get a clean, plain-language privacy-policy section plus a reviewer-notes block telling your lawyer exactly what to verify. A compliant-style draft, not legal advice.

View promptGemini 3 Pro Preview
Keep reading
Our Support Bot Confidently Made Up Enterprise Pricing — One System Prompt Fixed It

The agent wasn't hallucinating wildly, it was extrapolating plausibly. That's worse. Here's the exact system prompt that taught it to know its own limits.

Elite Prompting: Why Better Prompts Beat Random AI Instructions
I Designed Branded Wrapping Paper for My Candle Business for $28, Not $400

Packaging is part of my product, but a custom print run starts around $400. Print-on-demand plus one seamless-tile prompt got me there for the price of lunch.

Related prompts
Start in two minutes

Find a verified prompt for the job.