/privacy
When the user wants to create, optimize, or structure Privacy Policy page. Also use when the user mentions "privacy policy," "privacy page," "data protection," "GDPR compliance," "privacy notice," "data privacy," "CCPA," "cookie policy," or "personal data." For legal overview
$ npx -y skills add kostja94/marketing-skills --skill privacy --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
- You can call itInvoke it directly when you want it.
- Slash command
/privacy
Context preview
The summary Claude sees to decide when to auto-load this skill.
When the user wants to create, optimize, or structure Privacy Policy page. Also use when the user mentions "privacy policy," "privacy page," "data protection," "GDPR compliance," "privacy notice," "data privacy," "CCPA," "cookie policy," or "personal data." For legal overview
SKILL.md
privacy.SKILL.mdname: privacy-page-generator
description: When the user wants to create, optimize, or structure Privacy Policy page. Also use when the user mentions "privacy policy," "privacy page," "data protection," "GDPR compliance," "privacy notice," "data privacy," "CCPA," "cookie policy," or "personal data." For legal overview page, use legal-page-generator.
metadata:
version: 1.1.0
Pages: Privacy Policy
Guides Privacy Policy page content, structure, compliance, and AI-specific disclosures.
**When invoking**: On **first use**, if helpful, open with 1–2 sentences on what this skill covers and why it matters, then provide the main output. On **subsequent use** or when the user asks to skip, go directly to the main output.
Initial Assessment
Identify: 1. **Product category**: Free anonymous, free with account, freemium, subscription SaaS, enterprise/B2B, API/developer, marketplace, e-commerce, content/media, mobile app, AI agent/MCP — see legal-page-generator §Product Categories 2. **Data actually collected**: URLs, prompts, uploads, analytics, cookies, account data, payment data — be exhaustive 3. **AI involvement**: Whether AI models process user data and whether data is used for training (see §AI Disclosures) 4. **Jurisdiction needs**: Which privacy regulations apply — see legal-page-generator §Jurisdiction Decision Framework 5. **Indexing**: Typically index (see legal-page-generator §Indexing Strategy)
---
Required Sections (14-Section Framework)
1. Who We Are
- Operator name (or "the operator of [Product]" for anonymous operations)
- Tool purpose in one plain-language sentence
- Contact email
2. What [Product] Does
- One paragraph explaining the core function
- Mention that no account or payment is required (if applicable)
- Set expectations: this is a [free/paid] [tool type] that does [X]
3. Information We Collect
Structure with clear sub-sections:
**What We Do NOT Collect** (trust signal — include for all products):
- No accounts, no passwords, no user profiles
- No payment information (if free)
- No contact lists or address books
- No precise location data
- Adapt this list to what's actually true for the product
**Data You Submit** (URLs, prompts, uploads, form inputs):
- What happens to it: processed for [purpose], sent to [AI providers if applicable]
- Whether it's stored: "processed in-memory and discarded after the request" or retention period
- Whether it's used for training: "not used to train AI models" (if true — state explicitly)
**Generated Content** (AI output, images, text):
- Returned to user's browser/account
- Whether retained on servers
- Whether used for training
**Analytics Data**:
- Which analytics tool (GA4, Plausible, etc.)
- What's collected (page views, device/browser, referrer, country-level location, session duration)
- Whether it identifies individuals
**Account Data** (if applicable):
- Email, username, profile information
- How it's used and stored
**Payment Data** (if applicable):
- Note that payment is processed by [processor], not stored directly
4. How We Use Information
- Purposes: service provision, improvement, security, analytics, legal compliance
- **AI Model Training Disclosure**: State explicitly whether user data is used to train, improve, or fine-tune AI models. If using API-based AI (OpenAI API, Google Cloud), note that these providers do not train on API data. If using consumer AI tools, disclose that training may occur.
- Marketing communications (with consent where required)
5. Cookies
Table format with opt-out instructions:
| Cookie | Purpose | Duration | How to Opt Out | |--------|---------|----------|----------------| | `_ga`, `_ga_*` | Google Analytics — aggregate usage measurement | Up to 2 years | [GA opt-out browser add-on](https://tools.google.com/dlpage/gaoptout) or block third-party cookies | | `[session_cookie]` | Session management / fair-use enforcement | 24 hours / session | Clear browser data |
Also state:
- Whether advertising cookies are used
- Whether cross-site tracking occurs
- Whether the site responds to Do Not Track signals
6. Third-Party Processors
Table format with privacy policy URLs:
| Provider | Purpose | Privacy Policy | |----------|---------|----------------| | [Cloud provider] | Hosting / backend | [URL] | | [CDN provider] | Content delivery / routing | [URL] | | [AI model provider 1] | AI generation / processing | [URL] | | [AI model provider 2] | AI generation / processing | [URL] | | [Analytics provider] | Usage analytics | [URL] |
7. Data Retention
Specify per category — avoid vague "as long as needed" language:
- **Submitted data** (URLs, prompts, uploads): processed in-memory, discarded after response — not stored
- **Generated content**: delivered to browser, not retained on servers
- **Analytics aggregates**: retained for [X] months (GA4 default: 14 months)
- **Server access logs**: retained for 30 days for security/debugging
- **Account data** (if applicable): retained until account deletion; then deleted within [X] days
8. Your Rights
Structure by jurisdiction:
**GDPR (EEA/UK)**:
- Rights: access, rectification, erasure, restriction, portability, objection
- Legal basis for processing (Art. 6)
- Right to lodge complaint with supervisory authority
- Response timeframe: 30 days
**CCPA (California)**:
- Rights: know, delete, correct, opt-out of sale/sharing
- Statement: "[Product] does not sell personal information"
- How to exercise rights
**How to Exercise**:
- Email contact
- Identity verification if needed (note: for anonymous tools, minimal data exists)
9. International Transfers
- Where data is processed (country/region)
- Safeguards: Standard Contractual Clauses, adequacy decisions, or other mechanisms
- Note that data may transit through other regions as part of standard internet routing
10. Children
- Age threshold: under 13 (US/COPPA) or under 16 (EEA/GDPR)
- Statement: "not directed to children" / "do n
Read more
name: privacy-page-generator description: When the user wants to create, optimize, or structure Privacy Policy page. Also use when the user mentions "privacy policy," "privacy page," "data protection," "GDPR compliance," "privacy notice," "data privacy," "CCPA," "cookie policy," or "personal data." For legal overview page, use legal-page-generator. metadata: version: 1.1.0
Pages: Privacy Policy
Guides Privacy Policy page content, structure, compliance, and AI-specific disclosures.
**When invoking**: On **first use**, if helpful, open with 1–2 sentences on what this skill covers and why it matters, then provide the main output. On **subsequent use** or when the user asks to skip, go directly to the main output.
Initial Assessment
Identify: 1. **Product category**: Free anonymous, free with account, freemium, subscription SaaS, enterprise/B2B, API/developer, marketplace, e-commerce, content/media, mobile app, AI agent/MCP — see legal-page-generator §Product Categories 2. **Data actually collected**: URLs, prompts, uploads, analytics, cookies, account data, payment data — be exhaustive 3. **AI involvement**: Whether AI models process user data and whether data is used for training (see §AI Disclosures) 4. **Jurisdiction needs**: Which privacy regulations apply — see legal-page-generator §Jurisdiction Decision Framework 5. **Indexing**: Typically index (see legal-page-generator §Indexing Strategy)
---
Required Sections (14-Section Framework)
1. Who We Are
- Operator name (or "the operator of [Product]" for anonymous operations)
- Tool purpose in one plain-language sentence
- Contact email
2. What [Product] Does
- One paragraph explaining the core function
- Mention that no account or payment is required (if applicable)
- Set expectations: this is a [free/paid] [tool type] that does [X]
3. Information We Collect
Structure with clear sub-sections:
**What We Do NOT Collect** (trust signal — include for all products):
- No accounts, no passwords, no user profiles
- No payment information (if free)
- No contact lists or address books
- No precise location data
- Adapt this list to what's actually true for the product
**Data You Submit** (URLs, prompts, uploads, form inputs):
- What happens to it: processed for [purpose], sent to [AI providers if applicable]
- Whether it's stored: "processed in-memory and discarded after the request" or retention period
- Whether it's used for training: "not used to train AI models" (if true — state explicitly)
**Generated Content** (AI output, images, text):
- Returned to user's browser/account
- Whether retained on servers
- Whether used for training
**Analytics Data**:
- Which analytics tool (GA4, Plausible, etc.)
- What's collected (page views, device/browser, referrer, country-level location, session duration)
- Whether it identifies individuals
**Account Data** (if applicable):
- Email, username, profile information
- How it's used and stored
**Payment Data** (if applicable):
- Note that payment is processed by [processor], not stored directly
4. How We Use Information
- Purposes: service provision, improvement, security, analytics, legal compliance
- **AI Model Training Disclosure**: State explicitly whether user data is used to train, improve, or fine-tune AI models. If using API-based AI (OpenAI API, Google Cloud), note that these providers do not train on API data. If using consumer AI tools, disclose that training may occur.
- Marketing communications (with consent where required)
5. Cookies
Table format with opt-out instructions:
| Cookie | Purpose | Duration | How to Opt Out | |--------|---------|----------|----------------| | `_ga`, `_ga_*` | Google Analytics — aggregate usage measurement | Up to 2 years | [GA opt-out browser add-on](https://tools.google.com/dlpage/gaoptout) or block third-party cookies | | `[session_cookie]` | Session management / fair-use enforcement | 24 hours / session | Clear browser data |
Also state:
- Whether advertising cookies are used
- Whether cross-site tracking occurs
- Whether the site responds to Do Not Track signals
6. Third-Party Processors
Table format with privacy policy URLs:
| Provider | Purpose | Privacy Policy | |----------|---------|----------------| | [Cloud provider] | Hosting / backend | [URL] | | [CDN provider] | Content delivery / routing | [URL] | | [AI model provider 1] | AI generation / processing | [URL] | | [AI model provider 2] | AI generation / processing | [URL] | | [Analytics provider] | Usage analytics | [URL] |
7. Data Retention
Specify per category — avoid vague "as long as needed" language:
- **Submitted data** (URLs, prompts, uploads): processed in-memory, discarded after response — not stored
- **Generated content**: delivered to browser, not retained on servers
- **Analytics aggregates**: retained for [X] months (GA4 default: 14 months)
- **Server access logs**: retained for 30 days for security/debugging
- **Account data** (if applicable): retained until account deletion; then deleted within [X] days
8. Your Rights
Structure by jurisdiction:
**GDPR (EEA/UK)**:
- Rights: access, rectification, erasure, restriction, portability, objection
- Legal basis for processing (Art. 6)
- Right to lodge complaint with supervisory authority
- Response timeframe: 30 days
**CCPA (California)**:
- Rights: know, delete, correct, opt-out of sale/sharing
- Statement: "[Product] does not sell personal information"
- How to exercise rights
**How to Exercise**:
- Email contact
- Identity verification if needed (note: for anonymous tools, minimal data exists)
9. International Transfers
- Where data is processed (country/region)
- Safeguards: Standard Contractual Clauses, adequacy decisions, or other mechanisms
- Note that data may transit through other regions as part of standard internet routing
10. Children
- Age threshold: under 13 (US/COPPA) or under 16 (EEA/GDPR)
- Statement: "not directed to children" / "do n
Markdown skill library for AI agents - SEO, content, pages, paid ads, channels, strategies. Add project context + skills; your agent delivers tailored, production-ready output. Works with Cursor, Claude Code, OpenClaw, Lovable, and any AI that reads markdown.
Repo: kostja94/marketing-skills
Other skills on kostja94-marketing-skills.
- /google-search-console
When the user wants to analyze Google Search Console data, use the GSC API, or interpret search performance. Also use when the user mentions "GSC," "Search Console," "indexing report," "Core Web Vitals," "Enhancements," "Insights report," "search performance," "search queries,"
Open skill - /seo-monitoring
When the user wants to build an SEO data analysis system, monitor indexing/traffic/keywords/backlinks, or set up benchmarks. Also use when the user mentions "SEO data analysis," "SEO monitoring," "article database," "traffic benchmark," "penalty recovery," "SEO work document,"
Open skill - /ai-traffic
When the user wants to track AI search traffic in GA4 or GSC. Also use when the user mentions "AI traffic," "ChatGPT referral," "Perplexity traffic," "AI Overviews," "GA4 AI sources," "AI search analytics," "track AI referrals," "AI search traffic," "Claude traffic," or "how to
Open skill - /traffic
When the user wants to analyze website traffic sources, attribution, or dark traffic. Also use when the user mentions "traffic sources," "dark traffic," "direct traffic," "UTM parameters," "traffic attribution," "channel attribution," "attribution optimization," "channel
Open skill - /tracking
When the user wants to set up, audit, or optimize analytics tracking (GA4, events, conversions). Also use when the user mentions "Google Analytics," "GA4," "event tracking," "conversions," "attribution model," "gtag," "data layer," "GA4 setup," "conversion tracking," "event
Open skill - /community-forum
When the user wants to promote via forums, communities, or invite users to join a community. Also use when the user mentions "forum promotion," "Indie Hacker," "Hacker News," "community growth," "Discord promotion," "vertical community," "brand encyclopedia," "Wikipedia,"
Open skill

