Privacy Policy Completeness Checker
Published August 1, 2026
Paste your privacy policy below, select the data-protection laws that apply to your app or website, and get an instant completeness score. The checker scans your text against the required clauses for each selected regulation and returns a pass-or-missing checklist so you can see exactly what needs fixing. It also reports word count and a Flesch reading-ease score so you know whether your policy is understandable to a typical reader.
Your text stays private. This tool runs entirely in your browser. The policy text you paste is never sent to any server.
How to Use This Tool
Copy the full text of your existing privacy policy and paste it into the text box above. Then check every law that applies to your user base — if you are unsure, use the privacy law applicability checker first. If your app or website is directed at children or knowingly collects data from users under 13, set the children dropdown to "Yes." Click "Check My Privacy Policy" to see your score, a clause-by-clause breakdown showing which required disclosures are present and which are missing, plus a readability rating. If your score is low, you can generate a complete privacy policy that covers every clause automatically.
What the Completeness Score Means
The completeness score is the percentage of required clauses your policy covers for the laws you selected. A clause counts as "present" when the checker finds language in your policy that addresses that topic — for example, a mention of "data retention" or "how long we keep" satisfies the retention-period clause. The score is not a legal audit: it tells you whether the right topics are addressed, not whether the legal wording is perfect. A policy that scores 100% still needs review by someone who understands your specific data practices. A policy that scores below 60% is almost certainly missing disclosures that regulators expect to see.
The Flesch reading-ease score measures how easy your policy is to read. Most privacy policies land between 20 and 40, which is university-level difficulty. Regulators increasingly expect plain-language disclosures, so a score above 40 is a reasonable target. The word count is included because policies under 500 words are usually too thin to cover the required topics, while policies over 5,000 words may bury important disclosures in unnecessary length.
Clauses This Tool Checks
The checker evaluates twelve disclosure categories drawn from the text of the five supported regulations. Each law requires a different subset of these clauses, and the checklist labels every item with the specific law that mandates it:
- Lawful basis for processing — required by GDPR and LGPD. Your policy must state the legal ground for each type of data processing (consent, contract, legitimate interest, etc.).
- Categories of data collected — required by all five laws. List the types of personal data you collect (name, email, IP address, device identifiers, etc.).
- Data retention period — required by GDPR, CCPA/CPRA, PIPEDA, and LGPD. State how long you keep each category of data or the criteria used to determine the retention period.
- Third-party sharing — required by all five laws. Disclose which categories of third parties receive user data and for what purpose.
- International data transfers — required by GDPR and LGPD. If data crosses borders, explain the safeguards in place (adequacy decisions, standard contractual clauses, etc.).
- User rights — required by all five laws. Describe the rights users have (access, deletion, correction, portability, opt-out) and how to exercise them.
- "Do Not Sell or Share" opt-out — required by CCPA/CPRA. Provide an opt-out mechanism and clear disclosure about the sale or sharing of personal information.
- Children's data practices — required by COPPA. Describe parental consent mechanisms, what data is collected from children, and parents' right to review and delete it.
- Cookies and tracking technologies — required by GDPR. Explain what cookies and similar technologies you use and their purpose.
- Security measures — required by GDPR, PIPEDA, and LGPD. Describe the technical and organizational measures that protect user data.
- Contact information — required by all five laws. Provide a way for users to reach you about privacy concerns (email, postal address, DPO contact).
- Effective date — required by all five laws. Show when the policy was last updated or when it takes effect.
If you find your policy is missing several clauses, the fastest path to compliance is to read our guide on what an app privacy policy must include and then use the privacy policy generator to create a new policy that covers every required disclosure automatically.
Frequently Asked Questions
Does this tool store or transmit the privacy policy I paste?
No. The entire analysis runs in JavaScript inside your browser. Your policy text is never sent to any server, stored in any database, or shared with any third party. You can verify this by disconnecting from the internet before running the check.
Is a 100% completeness score the same as legal compliance?
No. The score tells you whether your policy text mentions the topics each law requires. It does not evaluate whether the wording is legally accurate, whether your stated practices match your actual practices, or whether sector-specific regulations (like HIPAA) impose additional requirements. Use this tool as a gap-finder, not as a substitute for qualified legal review.
Why does my policy score differently when I select more laws?
Each law requires a different set of clauses. When you select additional laws, the total number of required clauses increases. If your policy already covers those clauses, the score stays high. If the newly selected law requires clauses your policy does not address, the score drops. For example, adding COPPA introduces a children's data clause that many policies lack.
What is a good Flesch reading-ease score for a privacy policy?
Most privacy policies score between 20 and 40, which means they require a university-level reading ability. Regulators like the UK ICO and CNIL encourage plain-language policies. A score above 40 indicates your policy is more accessible than average. Extremely high scores (above 70) are unusual for legal documents and may indicate oversimplification.
Can I use this tool for a privacy policy that is not yet published?
Yes. Because you paste the text directly rather than entering a URL, you can check draft policies before they go live. This is useful for reviewing a policy during development or before submitting an app to the App Store or Google Play.