---
The mistakes that recur
Most privacy-policy problems are not malice; they are rushed templates. The same four errors show up across indie and small-team apps, and each is easy to fix once you look.
Mistake 1 — the policy contradicts the app
The policy says "we don't share data," but three SDKs ship events to ad networks. Reviewers and users notice. The fix is to audit dependencies and write the policy to match reality, not aspiration.
Mistake 2 — copy-pasted boilerplate
A policy lifted from another app (or a 2019 template) rarely fits. It names the wrong company, omits your actual SDKs, and misses current requirements. A generator helps only if you answer truthfully about what you collect.
Mistake 3 — missing user-rights section
GDPR and CCPA give users access, deletion, and opt-out rights. A policy with no rights section is incomplete for EU/CA users and fails the basics. State the rights and how to exercise them.
Mistake 4 — no lawful basis for EU users
Under GDPR you need a documented legal basis (consent, contract, legitimate interest) per purpose. Skipping this makes the EU section unenforceable. Even a one-line basis per purpose closes the gap.
Closing the loop
Write the policy from your real data map, disclose SDKs, add the rights section, and state lawful bases. A template gets you 80% of the way; honest inputs and counsel review close the rest.
Authoritative references
- GDPR Art. 12–14: https://gdpr-info.eu/art-12-gdpr/
- Cal. Civ. Code §1798.155 (CCPA remedies): https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=CIV&division=3.&title=1.81.5
- FTC business guidance: https://www.ftc.gov/business-guidance