✳ freem.ai 10000app 计划The 10000app Program
实用指南Guide

独立开发者的隐私政策:最少要写清哪几件事Privacy policy for indie makers: the parts that actually matter

我只是个人开发者,隐私政策到底该写什么?I'm a solo developer — what does my privacy policy actually need to say?

必答的五个问题The five questions it must answer

一份可用的隐私政策,本质上是老实回答五个问题:收集了什么数据、为什么收集、存在哪里存多久、和谁共享(分析、支付、云服务商都算)、用户如何查看与删除自己的数据。任何模板如果没回答这五条,都是摆设。A usable privacy policy honestly answers five questions: what data you collect, why, where and how long you keep it, who you share it with (analytics, payments and cloud vendors all count), and how users can see or delete their data. Any template that skips these is decoration.

错误一:抄一份和你实际做法不符的模板Mistake 1: copying a template that doesn't match reality

最常见也最危险的错误:抄来的政策写着「我们不使用 cookie」,而你的站点接了统计脚本。政策的法律风险不在写得简陋,而在写的和做的不一致。先列出你实际用到的第三方服务(分析、支付、邮件、CDN),再写政策。The most common and most dangerous mistake: a copied policy that says "we don't use cookies" while your site loads an analytics script. The legal exposure comes from the mismatch, not from being brief. List the third-party services you actually use — analytics, payments, email, CDN — before writing anything.

错误二:没有可用的联系方式Mistake 2: no working contact route

用户要行使权利(查看/删除数据)时必须有地方可找。一个真实在用的邮箱地址是最低要求;写了却不看邮件,比不写更糟。Users exercising their rights need somewhere to go. A real, monitored email address is the minimum; listing one you never read is worse than listing none.

错误三:把「合规」当成一次性任务Mistake 3: treating compliance as one-time

接入新的第三方服务、增加新的数据收集,政策就该更新。给自己定一条简单规则:每次接入新服务时顺手看一眼政策。另外,不要在政策里声称符合某部具体法规——除非你确实做过对应的合规工作。Adding a new vendor or a new data collection means the policy should change. Give yourself one rule: glance at the policy whenever you integrate something new. And never claim compliance with a specific law unless you have actually done that work.

不想自己一条条对?Don't want to do this by hand?

隐私政策免费,$1 四件套。Privacy policy free; 4-doc pack for $1.

打开 PolicyKit · 合规文本 →Open PolicyKit · Legal pages →
每周一封:这周做了什么、砍了什么、赚了多少Weekly: what we shipped, what we killed, what it earned