Free website legal pages, drafted to your actual site
The legal pages your website needs
GitLaw's AI Agent drafts your website's privacy policy, cookie policy or terms of service in minutes, matched to your business, your stack and your jurisdiction.
5.0 out of 5 on Google
Read reviewsAs featured in








One page, or the whole pack
Start with your privacy policy. Add the pack when you're ready.
Checkbox generators can't see your business. GitLaw reads what your site actually does and drafts pages that fit, ready in minutes. A preview, not legal advice.
Previewing legal pages for examplecompany.com: a design studio with a client login · drafted 16 September 2026
PRIVACY POLICY: examplecompany.com Last updated: 16 September 2026 1. WHO WE ARE This notice explains how examplecompany.com, a design studio with a client login, collects and uses personal data, and who is responsible for it. 2. WHAT WE COLLECT, AND THE LAWFUL BASIS For each thing your site actually does (contact forms, analytics, accounts, payments), GitLaw lists the data collected and the lawful basis for it, rather than a generic catch-all. 3. YOUR RIGHTS AND HOW TO COMPLAIN Access, correction, deletion and the route to the relevant regulator, the ICO in the UK, or the state attorney general or privacy agency in the US. 4. COOKIES A short summary that points to your cookie policy. Drafted to what your site does. Free to start, edit through chat. Not legal advice.
WEBSITE LEGAL PACK Privacy policy, cookie policy and terms, drafted one at a time and kept together in one workspace. Each one matched to your stack and jurisdiction. 1. Privacy policy. What you collect, why, who you share it with and how long you keep it. 2. Cookie policy. Which cookies you set, what they do and how visitors manage consent. 3. Terms of service. Acceptable use, payment and refunds, liability and governing law. Start with one. Add the next from the same workspace in a couple of clicks.
CLIENT-SITE PACKS Draft policies for every client site you build, each one matched to that client’s stack and jurisdiction, all stored in one workspace. How it works: 1. Draft the client’s privacy policy from what their site actually does. 2. Add their cookie policy and terms from the same workspace. 3. Keep each client’s documents separate, and hand them over when the build ships.
Which legal pages does your site need?
Most sites need two or three. Pick one, GitLaw drafts it, then add the next from the same workspace.
| Document | When your site usually needs it | What it covers |
|---|---|---|
| Privacy policyDraft my privacy policy | You collect any personal data: sign-ups, contact forms, analytics, payments. Expected under UK GDPR, EU GDPR and the 20 US states with privacy laws. | What data you collect, why, who you share it with, how long you keep it, and how visitors can exercise their rights. |
| Cookie policyDraft my cookie policy | You use cookies or tracking beyond what the site strictly needs to run: analytics, ads, embedded video, chat widgets. UK rules changed in Feb 2026. | Which cookies you set, what they do, how long they last, and how visitors can manage consent. |
| Terms of serviceDraft my terms of service | You sell, subscribe, take payments, host user content or run a client portal. Not mandated by law, but commonly used to set the rules of use, liability and payment. | Acceptable use, payment and refunds, limits on liability, governing law and how disputes are handled. |
One document per draft. Add the rest from your workspace in a couple of clicks.
What a generic policy misses
Checkbox generators ask 'Google Analytics? ☐'. They can't see that you hold client data, take deposits or run analytics for other people. A policy that doesn't match your site is one a regulator, or a client, can see straight through.
MultiState 2026 state-privacy tracker; Data Use and Access Act 2025 (gov.uk); Companies Act 2006 trading-disclosure requirements. Figures change. GitLaw drafts to current law, and this is not legal advice.
Draft my documentNot another checkbox generator
GitLaw is an AI legal agent. It reads your site, then drafts.
Describe what your website does in plain English. GitLaw works out which pages you need, drafts them to your actual stack and jurisdiction, and keeps them in a workspace you can reuse for the next site.
Built for your legal work,
with practicing lawyers
Trained on 5,500+ clauses and specialist areas of law. Built with a standards committee of independent lawyers.



Trusted by 5,000+ businesses


GitLaw drafts with trusted templates from its library
Browse all templatesFrequently asked questions
In practice, yes. If your site collects any personal data, even names through a contact form, the UK GDPR and the growing set of US state privacy laws expect a privacy notice, and California's CalOPPA requires a posted policy for sites that collect personal information. The real question is rarely whether you need one, but whether yours matches what your site actually does.
They're a fine starting point, but many produce boilerplate that names only California or ignores cookies entirely, and some carry their own disclaimer that the output isn't legal advice and is used at your own risk. The weakness is fit: a checkbox tool can't see that you hold client data or take payments. GitLaw drafts from what your site actually does, one document at a time, and you can still have a lawyer review the result.
Nothing legal. Terms of service, terms of use and T&Cs are interchangeable names for the contract between your site and its visitors. What matters is the content: acceptable use, limits on liability, intellectual property, governing law and, if you sell, consumer-law terms. GitLaw drafts the terms your site's activity calls for, whatever you label them.
Terms aren't mandatory just to have a website, but they matter the moment you sell, host user content or want to limit your liability, and UK consumer law makes certain pre-contract information mandatory if you sell to consumers. Terms are generally enforceable where visitors have reasonable notice and accept them. You don't need a lawyer to start, but a review before you rely on them is sensible.
For advertising and tracking cookies, yes: you still need consent. The Data Use and Access Act 2025 carved out some first-party analytics and functionality cookies from the prior-consent rule where conditions are met (clear information and an easy opt-out). It narrows what needs a banner; it doesn't remove banners. In the US there's no federal banner rule, but several state laws require you to honour opt-out-of-sale/share signals.
It can. The GDPR reaches organisations outside the EU where they offer goods or services to, or monitor the behaviour of, people in the EU, so an agency or shop that targets EU customers may be in scope even without an EU office. Whether you're caught depends on what you do, not just where you're based. GitLaw asks about your audience before it drafts.
Under the Companies Act trading-disclosure rules, a UK limited company must show its registered company name, company number, place of registration and registered office address on its website, plus contact and VAT details where relevant. Most privacy-policy generators skip this entirely. GitLaw builds it into your terms and site footer text.
Yes. Each site's pages should reflect that site's business and data, so a shared or copied policy is a poor fit and a real risk. GitLaw is built for this: re-run the pack per client site, and the documents belong to the client rather than sitting inside a subscription you resell. No per-site licence.
GitLaw drafts one document per run, so each one is matched properly to your stack and jurisdiction. Start with your privacy policy, then add your cookie policy and terms from the same workspace. Each takes a few minutes.
More free legal tools
Legal pages that fit your site.
Tell GitLaw what your website does and it drafts the document to match, ready in minutes.
