Terms of Service & Privacy Policy is a Claude AI skill — drafts both documents from your product type, data handling, user relationship, and jurisdiction. Starting point for review, not a substitute for legal counsel on complex products.
A SaaS founder launches their product. They need a ToS and a Privacy Policy before they can go live. They find a well-designed competitor in their space, inspect the source, copy the legal documents, swap the company name, update the product name in a few places, and ship. It takes 25 minutes. The documents look professional. The product launches.
Eighteen months later, a user complaint surfaces about how their data was used during a product trial. The founder pulls up the Privacy Policy to check what it says. It describes a data retention model the product doesn't actually use. It references a third-party analytics tool the competitor uses but this product doesn't. It's missing the disclosure about the AI processing pipeline that this product runs every user submission through — because the competitor's product doesn't have one.
The documents weren't fraudulent. They were accurate for a different product. The founder had been publishing legal commitments about a product that didn't exist, in a company that wasn't theirs.
What You Actually Inherit When You Copy a ToS
A Terms of Service and Privacy Policy are descriptions of your product's relationship with users. They specify what you can do with user data, what liability you accept and disclaim, what happens when things go wrong, and what recourse users have. Copied from another product, they describe that product's relationship with its users — which may resemble yours in some ways and differ from it in others that matter considerably.
The differences that matter most aren't visible without knowing both products in detail. A B2B SaaS that processes client data on behalf of enterprise customers operates as a data processor under GDPR — which requires specific contractual language about processing, sub-processors, and data subject rights that a B2C consumer app has no reason to include. An AI-powered product that runs user inputs through a large language model has data handling obligations around training data use, automated decision-making, and output ownership that a static software product doesn't face. A subscription product with auto-renewal has specific disclosure requirements in several US states and the EU that a one-time purchase product can ignore.
Legal documents describe what your product actually does with users and their data. Copying them from another product means publishing a description of a product you don't run — which is both inaccurate and, in regulated jurisdictions, a compliance problem in its own right.
The Privacy Policy problem is often more acute than the ToS problem, because privacy regulations — GDPR, UK GDPR, CCPA, Australia's Privacy Act — specify what disclosures must appear, what they must say, and what they must be accurate about. A Privacy Policy that describes a data flow you don't have, or omits one you do, isn't a minor oversight. In jurisdictions where data protection authorities have enforcement powers, it's a compliance gap with real consequences.
That gap is exactly what the Terms of Service & Privacy Policy skill for Claude was built to close.
What Drafting from Your Product Actually Changes
Before the NovaKit Terms of Service & Privacy Policy skill writes a single clause, it maps your product's actual parameters: what type of product it is and how users interact with it, what data is collected and how it's processed, whether you're operating as a controller or processor under applicable privacy law, which jurisdictions your users are in, and whether the product includes subscription billing, user-generated content, AI processing, or other feature categories that carry specific disclosure requirements.
Those inputs produce documents that describe your product rather than a hypothetical average product. The data collected section of the Privacy Policy lists what you actually collect. The third-party services section names the processors you actually use. The liability disclaimers in the ToS reflect the actual risk profile of your product type. The subscription and billing terms, if present, match your billing model.
A ToS that describes your product is protection. A ToS that describes someone else's product is paperwork that creates its own compliance exposure.
The skill also surfaces jurisdiction-specific requirements as flagged review notes — GDPR controller vs. processor classification, CCPA opt-out requirements, UK ICO registration obligations — so you know exactly where the documents need verification rather than discovering it through a complaint or regulatory query.
What the ToS & Privacy Policy Skill Produces
The skill's interview covers six inputs: product type, data collected and how it's processed, user relationship (B2C consumer, B2B business, marketplace, or platform), billing model if any, AI or automated processing if present, and primary jurisdiction of the operator and users. From those:
Copied ToS vs Calibrated Draft — Privacy Policy Data Section
Same product type — a B2B SaaS that processes client documents through an AI pipeline — with a copied Privacy Policy versus one produced by the skill. The difference is most visible in the data collection and processing section, where a copied document describes whatever the source product does.
We collect information you provide directly to us, such as when you create an account, make a purchase, or contact us for support. This may include your name, email address, password, and payment information.
We also collect information automatically when you use our services, including log data, device information, and cookies. We may use third-party analytics services to help understand usage of our services.
— Standard consumer SaaS template. No mention of document processing, AI pipeline, or B2B data processor obligations.
Account data: Name, business email, company name, and billing information provided at registration.
Documents you submit: Files and content uploaded for processing through our AI pipeline. These are processed to provide the service and are not used to train our models without your explicit consent. Documents are retained for [X] days following processing unless you delete them earlier.
Processing data: Logs of processing jobs, output files generated, and usage metrics. We act as a data processor for any personal data contained within documents you submit; your organisation remains the data controller.
📍 Review note: If processing documents containing personal data of EU residents, a Data Processing Agreement (DPA) with your customers is required under GDPR Art. 28. This policy addresses your own data practices; a DPA template covers your obligations to customers as processor.
The copied version covers account data and analytics in language suitable for a consumer app. The calibrated draft describes what this product actually does — document ingestion, AI processing, output generation, and the controller/processor distinction that determines GDPR obligations — and flags the downstream requirement (a customer-facing DPA) that the Privacy Policy alone can't address. One is accurate for a different product. The other is accurate for this one.
Who Gets the Most from This Skill
Early-stage SaaS and app founders who need accurate legal documents before launch and currently have a copied ToS that doesn't describe their product. Indie developers and no-code builders launching products that process user data and need privacy disclosures that reflect what their product actually does. Founders updating documents after a significant product change — new billing model, AI features added, new market entered — where the old ToS no longer accurately describes the current product.
The skill produces a starting point, not a finished document. For products operating in regulated industries (fintech, healthtech, edtech serving minors), handling sensitive data categories, or serving enterprise customers who will scrutinise the documents as part of their vendor assessment, professional legal review of the output is the right next step. The skill's value there is arriving at that review with a well-structured, product-accurate draft rather than a blank page or a document that describes a different company's product entirely.
The Output You Walk Away With
Both documents in one run: a complete Terms of Service and a complete Privacy Policy, each calibrated to your six inputs, with an AI processing addendum where applicable, inline jurisdiction flags on the provisions that carry regulatory requirements, and review annotations on the clauses most likely to need attention for your specific product type. Formatted and ready to paste directly into your website CMS, legal page, or a document for lawyer review.
The path from download to result is straightforward: run the skill with your product's actual parameters, review the flagged annotations, update the bracketed placeholders (retention periods, contact details, specific processor names), and publish. If a lawyer is in the loop, hand them the flagged sections rather than asking them to review everything from scratch.
Legal documents that accurately describe your product aren't just a compliance requirement. They're the version of your company's commitments you can actually stand behind when a user or a regulator reads them carefully. The copied ToS gets you through launch. The calibrated draft gets you through everything that comes after.
The next piece most people tackle from here is a grant proposal structured around what reviewers score.
Put this to work: the Terms of Service & Privacy Policy skill for Claude turns everything above into one guided workflow you run in a normal Claude chat. Not ready to buy? Start with a free Claude skill and see how it works first.
Related reading: Five Things a Copied Terms of Service Fails to Cover — and When They Surface