Skills
Privacy Policy Generator
A practice-area skill: it carries legal knowledge — a doctrine, a regime, a review standard — and applies it to your material.
What this skill does
Generate a jurisdiction-aware privacy policy through a guided intake that states only what you confirm. Covers GDPR/EU + UK, US (CCPA/CPRA + ~20 state laws + COPPA + sector overlays like HIPAA/GLBA/BIPA), and global/MENA (Brazil, Canada, Australia, India, UAE/DIFC/Saudi), plus app-store, cookies/consent, and AI/LLM disclosures. Built for zero hallucination — every legal claim is grounded in a verified reference pack; it never invents a statute, citation, fine, or date.
Free, and published by its author - not by HAQQ. The link leaves this site.
Where it runs, and how to install it
Agent Skills are a format, not a product feature: a folder with a SKILL.md and whatever files it needs. Nothing inside one is model-specific.
- Claude
- Drop the skill folder into ~/.claude/skills/, or upload it in Settings → Capabilities. Claude loads it when the description matches what you asked for.
- Claude Code
- Same folder, per-project instead: .claude/skills/ inside the repository, so the skill travels with the work rather than with the machine.
- Any agent that reads SKILL.md
- A skill is a folder with a SKILL.md and whatever files it needs. Nothing in the format is model-specific, so a runtime that reads the file reads the skill.
More from Stephane Boghossian
- Connecticut Divorce PlannerClaude skill that turns Claude into a Connecticut-specific divorce planner — nine operating modes from pre-flight intake to post-judgment modification, modeled on Untangle.us's feature surface and grounded in C.G.S. Title 46b, Practice Book Chapter 25, and the 2026-08-01 CCSG schedule. Covers eligibility triage (nonadversarial under § 46b-44a vs standard), financial affidavit (JD-FM-6), child supp
- Fintech Agreement DraftingDrafting copilot for complex, multi-pillar regulated fintech agreements — where a licensed payment-services provider engages a counterparty across several service lines (agent cash-in/cash-out, QR payments, wallet e-payments, marketplace), each with its own regulatory profile. Encodes a repeatable end-to-end method from intake and regulatory mapping through framework architecture, ring-fencing, drafting, and signature across five phases and fourteen steps.
- cite-guardPaste an AI-drafted legal filing and cite-guard extracts every case citation, checks each against a known-cases index, and returns a single hallucination-risk score plus a per-citation verdict — verified, unverified, or fabricated. One number tells you whether a brief is safe to file. Open source, built to stop the fabricated citations courts have sanctioned lawyers for filing.
- Billable TimeWhen your bar comes asking "show me how you billed AI-assisted work" — and ABA 512, Florida 24-1, California, New York, and DC all have opinions out — you need an artifact that survives review. billable-time produces it. From your Claude Code session logs, it drafts reviewable time entries plus a printable HTML audit packet with: SHA-256 chain of evidence (source files + matter.yml + active disclosure pack + verifiable artifact self-hash), attorney identity and signature block, a bar-opinion disclosure pack with starter language for five jurisdictions, and content-aware deterministic narratives derived from filename and tool shape — never from prompt text by default. The tool refuses to bill on its own. --strict mode refuses to ship the artifact if any audit invariant fails (broad routes, missing attorney, missing/unverified disclosure). Comes as a Node CLI and a self-contained browser version (no backend; JSONL never leaves the page). 15 invariant tests verify the contract. AGPL-3.0.
- IRAC Prompt BuilderRestructure any rough build, research, or legal-drafting request into an IRAC-shaped prompt — Issue, Rule, Analysis, Conclusion — optimized for a frontier model. It's the bar-exam framework, repurposed as prompt engineering. The skill leads with the issue and ends with the conclusion (where models weight attention most), forces you to name your constraints and non-goals, and specifies what "good" looks like before a single token is generated. Use it before any non-trivial build, or whenever a vague ask deserves a precise brief.
- Oral ArgumentTribunal-prep skill modeled on Neal Katyal's Nov 2025 SCOTUS tariffs argument and his AI sparring partner "Harvey." Five phases: (1) profile each decision-maker from prior opinions, questions, concurrences, and dissents — surface their doctrinal commitments and institutional concerns; (2) predict the bench — 3–7 likely questions per judge with the worry behind each, verbatim phrasing where confidence is high; (3) map escape routes — the narrowest holding each skeptical judge could sign without abandoning prior commitments; (4) spar adversarially — relentless follow-ups, calls out parroted lines, tracks which questions broke the lawyer; (5) hand the lawyer back to themselves with a < 150-word index card for the podium. The model is the sparring partner. The lawyer still wins the case. Use for oral argument, motion hearings, depositions, arbitrations, or stress-testing a brief before filing.
Skills that do related work
- Azerbaijan + EU Website Privacy Compliance AuditAudits a website for compliance with Azerbaijan's Law on Personal Data No. 998-IIIQ and, where applicable, EU GDPR plus ePrivacy/cookie consent rules. Inventori
- Dpa ReviewReview a Data Processing Agreement against your DPA playbook — auto-detects whether you're processor or controller and applies the right half of the playbook. U
- DPDPA & GDPR Compliance ReviewPerforms structured compliance review, clause redlining, and drafting suggestions for legal documents (privacy policies, data processing agreements, vendor and
- DPIA SentinelGDPR Data Protection Impact Assessment (DPIA) guidance under Article 35 GDPR, EDPB Guidelines WP 248 rev.01, EDPB Opinion 28/2024 (AI), and national SA blacklis
- Dsar ResponseWalk through a Data Subject Access Request (or deletion, portability, correction request) and draft the response — verify identity, locate data system-by-system
- GDPR Breach SentinelIncident response and legal compliance guidance for data breaches under GDPR Articles 33 & 34. Covers breach risk assessment using ENISA severity methodology, C