Generate privacy policies, ToS, EULAs, cookie policies & disclaimers from your AI agent.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
π‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
Give your AI agent the power to generate privacy policies, terms of service, EULAs, cookie policies, and disclaimers β while it builds your app.
Powered by PrivacyPage. Free instant previews; unlock the full document for a one-time $9.99 (no subscription, no account).
Every app shipped from Cursor, Lovable, Bolt, or v0 eventually needs legal documents β the App Store and Play Store require a privacy policy, GDPR requires cookie disclosures, and users expect terms of service. This MCP server lets the agent that's building your app generate those documents in the same conversation, filled in from what the agent already knows about your app: its name, platform, the data it collects, and the SDKs it uses.
Requires Node.js 18+. No API key needed to generate previews.
Add to ~/.cursor/mcp.json (or .cursor/mcp.json in your project):
Add to claude_desktop_config.json (Settings β Developer β Edit Config):
| Tool | What it generates | Key inputs |
|---|---|---|
generate_privacy_policy | GDPR/CCPA/COPPA-aware privacy policy | app name, platform, company, contact email, data collected, third-party SDKs, children under 13 |
generate_terms_of_service | Terms of Service agreement | service name, company, platform, key policies (refunds, UGC, subscriptionsβ¦), jurisdiction |
generate_eula | End-User License Agreement | app name, company, platform, license type, usage restrictions |
generate_cookie_policy | GDPR-aware cookie policy | website name/URL, cookie types, third-party services, contact email |
generate_disclaimer | Liability disclaimer (general / medical / financial / fitness / legal / affiliate) | site name, disclaimer type, external links, contact email |
get_full_document | Full text of any generated document | documentId + license key (argument or PRIVACYPAGE_LICENSE_KEY env var) |
Every generate_* tool returns a free 25-line preview, a documentId, and instructions for unlocking the full document.
You: Ship my fitness tracker app to the App Store. It uses Firebase Analytics and HealthKit.
Agent: The App Store requires a privacy policy. Let me generate one. (calls
generate_privacy_policywithappName: "FitTrack",platform: "iOS",dataCollected: ["Health Data", "Usage Analytics"],thirdPartyServices: ["Google Analytics / Firebase"],childrenUnder13: false)Agent: Here's a preview of your privacy policy β it covers HealthKit data, Firebase, GDPR and CCPA rights, and COPPA. To get the full document, purchase a one-time license at privacypage.io ($9.99, no subscription) and give me the key.
You: Here's my key:
PP-XXXX-XXXXAgent: (calls
get_full_document) Done β I've saved the full policy topublic/privacy-policy.mdand linked it in your app's settings screen.
PRIVACYPAGE_LICENSE_KEY in your MCP config and the agent can unlock full documents automatically.Rate limit: 10 document generations per hour per IP. The server reports rate-limit errors to the agent with a friendly retry message.
| Variable | Purpose |
|---|---|
PRIVACYPAGE_LICENSE_KEY | Optional. License key used by get_full_document when no licenseKey argument is passed. |
PRIVACYPAGE_API_URL | Optional. Override the API base URL (defaults to https://privacypage.io). |
This server runs locally over stdio and makes HTTPS requests only to the PrivacyPage API (https://privacypage.io, or whatever PRIVACYPAGE_API_URL is set to). Everything below is verifiable in src/index.ts and src/api.ts.
What leaves your machine. Only the explicit arguments the agent passes to a tool call β the fields the generated document prints, such as app/site name, platform, company name, contact email, website URL, data-collection and cookie selections, key policies, and jurisdiction (varying by tool). For the generate_* tools these are sent as a plain JSON POST body; get_full_document sends the documentId and license key as query parameters on a GET request. No conversation context, no filesystem contents, and nothing else from the agent session is read or transmitted.
Schema-bounded. Each tool declares a fixed input schema, and every request payload is built field-by-field from those named arguments only. An agent has no channel to send extra context through these tools.
License key. PRIVACYPAGE_LICENSE_KEY (or the licenseKey argument) is sent only to the PrivacyPage API, solely to prove entitlement when fetching a full document.
What's stored server-side. The PrivacyPage service stores the generation inputs and the generated document β that's what lets a license key unlock a document by documentId after generation. This data is not used for analytics and is not shared. (Server-side behavior is a property of the privacypage.io service; this repository's source shows only what is sent.)
Rate limiting. Generation endpoints are limited to 10 document generations per hour per IP; the server reports 429 responses to the agent with a retry message.
Documents generated by PrivacyPage are professionally structured templates and AI-generated drafts. They are not legal advice; for high-stakes situations, have a lawyer review your documents.
MIT β the server. Generated documents are yours.
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/privacypage-mcp)<a href="https://allmcps.com/mcp/privacypage-mcp"><img src="https://allmcps.com/api/badge/privacypage-mcp?style=directory" alt="Privacypage MCP on AllMCPs" /></a>