我只是个人开发者,隐私政策到底该写什么?I'm a solo developer — what does my privacy policy actually need to say?
一份可用的隐私政策,本质上是老实回答五个问题:收集了什么数据、为什么收集、存在哪里存多久、和谁共享(分析、支付、云服务商都算)、用户如何查看与删除自己的数据。任何模板如果没回答这五条,都是摆设。A usable privacy policy honestly answers five questions: what data you collect, why, where and how long you keep it, who you share it with (analytics, payments and cloud vendors all count), and how users can see or delete their data. Any template that skips these is decoration.
最常见也最危险的错误:抄来的政策写着「我们不使用 cookie」,而你的站点接了统计脚本。政策的法律风险不在写得简陋,而在写的和做的不一致。先列出你实际用到的第三方服务(分析、支付、邮件、CDN),再写政策。The most common and most dangerous mistake: a copied policy that says "we don't use cookies" while your site loads an analytics script. The legal exposure comes from the mismatch, not from being brief. List the third-party services you actually use — analytics, payments, email, CDN — before writing anything.
用户要行使权利(查看/删除数据)时必须有地方可找。一个真实在用的邮箱地址是最低要求;写了却不看邮件,比不写更糟。Users exercising their rights need somewhere to go. A real, monitored email address is the minimum; listing one you never read is worse than listing none.
接入新的第三方服务、增加新的数据收集,政策就该更新。给自己定一条简单规则:每次接入新服务时顺手看一眼政策。另外,不要在政策里声称符合某部具体法规——除非你确实做过对应的合规工作。Adding a new vendor or a new data collection means the policy should change. Give yourself one rule: glance at the policy whenever you integrate something new. And never claim compliance with a specific law unless you have actually done that work.
隐私政策免费,$1 四件套。Privacy policy free; 4-doc pack for $1.
打开 PolicyKit · 合规文本 →Open PolicyKit · Legal pages →