# App Privacy Policy Generator: a static-site wizard for app policies

> The project turns a Go build pipeline and a browser wizard into HTML or Markdown privacy policies and terms for Android, iOS, KaiOS and web apps. It is free, AGPL-3.0 licensed, and accepts bug fixes only.

**nisrulz/app-privacy-policy-generator** — Generate a customized Privacy Policy and Terms of Use document for your mobile apps

- Repository: https://github.com/nisrulz/app-privacy-policy-generator
- Website: https://app-privacy-policy-generator.nisrulz.com/
- Stars: 4,690 · Forks: 469
- Language: HTML
- License: AGPL-3.0
- Published: 2026-09-23 · Updated: 2026-09-23 · Language: en
- Canonical page: https://hysenlabs.com/projects/nisrulz-app-privacy-policy-generator

## The gap this fills between a blank page and a lawyer

Store listings require a privacy policy URL. Writing one from scratch means covering data collection, third-party SDKs, consent age, location and personally identifiable information, and most solo developers put it off until submission day. This project is a wizard that asks those questions and emits a document. The README describes it as "a free, open-source web app to generate privacy policies and terms & conditions for your Android, iOS, KaiOS, and Web apps." The audience is narrow and obvious: indie developers and small teams shipping to app stores, plus anyone who wants the policy source under their own control rather than behind a form on someone else's domain. It is not a compliance product. It produces text from your answers, and the accuracy of that text is your responsibility.

## A Go build step, static output, and a wizard in the browser

The repository is not a server application. Top-level entries include cmd/, src/, public/, tools/ and tests/, and the Makefile drives a Go program under cmd/build/. That program compiles templates into the public/ directory, which is what gets served. The Go module pulls in tdewolff/minify for minification and toakleaf/less.go for stylesheet compilation, so the pipeline is doing real asset work rather than copying files. The wizard itself runs client-side, which is why the README says the app "works offline as a PWA". Nothing about your answers needs to leave the browser for a document to be produced. Deployment targets Firebase Hosting, visible in firebase.json and the two GitHub Actions workflows named for production and pull-request deploys. The practical consequence: there is no backend to operate, no database, and no account system, which also means no server-side record of what you generated.

## Installing it locally and generating a first policy

The README's Quick Start lists three commands and a Go version requirement of 1.25 or later. The build step writes into public/, then the serve target starts a dev server. Run these from the repository root:

```bash
make format
make check
make serve
```

make format runs gofmt over cmd/build and tools/reviews-page-generator, formats the templates in src/tpl, and tidies modules. make check runs go vet and go build, installs Chromium through Playwright, and runs the browser tests, so the first invocation downloads a browser. make serve builds and serves; the Makefile documents the dev server on port 8000 and shows an override, make serve PORT="9090". Open the printed address and the wizard appears. Select the data your app collects, pick one of the Simple, No Tracking or GDPR variants, and set options such as age of consent, AI disclosure, location tracking and PII fields. The README states the text adapts to mobile, web or combined platforms, and that you can export a preview, HTML or Markdown. For a static host, the output of make build is the deployable artifact:

```bash
make build
```

That command runs the Go builder without starting a server. If you only want the hosted version, the README points to app-privacy-policy-generator.nisrulz.com and no local setup is needed.

## What the generator cannot decide for you

The output is assembled from templates and your selections. It has no knowledge of which SDKs are compiled into your binary, so a policy that omits an advertising or analytics library is still a policy that omits it. The README lists the wizard's inputs but does not document a verification step against your dependency manifest, and it does not document rollback for a generated document. Treat the export as a first draft with the structure already in place. There is a second limitation that is easy to miss: the README states the project "accepts bug fixes only", with feature proposals routed to an issue first. If your requirement is a clause the templates do not cover, the upstream path is a discussion, not a pull request. Third, the generated text is not jurisdiction-specific legal advice, and the README makes no such claim. Teams with regulated data, minors in scope, or operations in multiple jurisdictions should have the result reviewed rather than published directly.

## How it differs from a hosted policy service

Hosted generators such as the commercial services people search for under the same phrase typically give you a hosted page, a stable URL, and sometimes an update mechanism when the law changes. This project gives you a file. That inverts the trade-off. You get the source, the ability to self-host, and no dependency on a vendor staying online, but you also own the hosting, the URL, and every future edit. The README's support section asks for sponsorship on the grounds that "servers and maintenance are not free", which is an honest signal that the hosted instance is a courtesy, not a contractual service. If you need someone else to keep the policy current, a commercial generator is the better fit. If you want the document in your own repository next to your app code, this is the more direct route.

## Licence, maintenance and the cost of running your own copy

The project is AGPL-3.0, and package.json carries the same identifier. That matters if you modify the code and make it available over a network: the AGPL's network clause is the reason some teams avoid it for anything they host publicly. Publishing generated policy text is a different question from distributing modified generator code, and the two should not be conflated. This is not legal advice; read LICENSE and, if your use is commercial and modified, get proper review. On maintenance: the repository is not archived, and the last push was on 2026-09-18. Releases are frequent in the recent record, with 5.2.0 on 2026-08-31, 5.1.0 on 2026-07-06 and 5.0.0 on 2026-05-25. Note that package.json still reports version 5.1.0 while the latest release is 5.2.0, so the two version numbers do not track each other. Upgrading a self-hosted copy means rerunning the build and redeploying public/; the Makefile also exposes targets for purging unused Bulma CSS and compressing images, and it warns that after a CSS purge you should run make build again to refresh cache-busting hashes. Budget for that as routine work, not a one-off.

## Conclusion

Adopt it if you ship a small Android, iOS or web app and need a policy document you can edit and host yourself. Skip it if you need jurisdiction-specific legal drafting, a hosted API, or a service that takes responsibility for the text. Before using the output, read the generated clauses against the third-party SDKs actually bundled in your build, and confirm which licence obligations AGPL-3.0 places on any modified copy you deploy.

## FAQ

### What is a privacy policy generator?

It is a tool that assembles a privacy policy document from answers you provide instead of asking you to write one from scratch. This project does that for Android, iOS, KaiOS and web apps, and exports the result as a preview, HTML or Markdown file.

### Does my app need a privacy policy?

The README does not discuss store requirements, so it cannot answer this for your case. What it does show is that the tool exists to produce the document, and that the wizard covers data collection, third-party services, age of consent, AI disclosure, location tracking and PII fields.

### Is the free app privacy policy generator from nisrulz legit?

The source is public under AGPL-3.0 at github.com/nisrulz/app-privacy-policy-generator, and the wizard runs in the browser, so nothing needs to be sent to a server for a document to be generated. The README makes no claim that the output is legally reviewed, so treat it as a draft.

## Sources

- [License: AGPL-3.0](https://github.com/nisrulz/app-privacy-policy-generator/blob/master/LICENSE)
- [nisrulz/app-privacy-policy-generator on GitHub](https://github.com/nisrulz/app-privacy-policy-generator)
- [Project website](https://app-privacy-policy-generator.nisrulz.com/)
- [README](https://github.com/nisrulz/app-privacy-policy-generator/blob/master/README.md)
- [Releases](https://github.com/nisrulz/app-privacy-policy-generator/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/nisrulz-app-privacy-policy-generator
