Guides / Ideas and launching

How to Write Terms of Service and a Privacy Policy for Your App

What terms of service and a privacy policy for your app usually contain, why each section matters, how to prepare a draft, and when to involve a lawyer.

Mythex Team · 2026-09-29 · 6 min read

This guide is not legal advice. It explains what terms of service and a privacy policy usually contain and why, so you can prepare a sensible draft and have a better conversation with a lawyer. The rules that apply to you depend on where your business is, where your users are, what data you collect and what you sell. For anything beyond a small, low-risk app — and ideally for that too — have a qualified lawyer review your documents.

The short version: your terms of service set the rules between you and your users. Your privacy policy explains, honestly, what personal data you collect and what you do with it. Both must describe what your app actually does.

Why these documents matter

  • Privacy laws. Many countries and regions have laws that require you to tell people what personal data you collect and why — the EU's GDPR is the best-known example (see what is GDPR).
  • Third parties require them. App stores, payment providers, ad platforms and login providers such as "Sign in with Google" commonly ask for a link to your privacy policy and sometimes your terms.
  • Disputes. Clear terms about payments, refunds and acceptable use make disagreements easier to resolve.
  • Trust. Customers, especially businesses, read these pages before they buy.

Before you write: map your data and business

You can't describe what you don't know. Write down:

  1. What personal data you collect — names, emails, payment details (usually handled by your payment provider), IP addresses, usage data, uploaded files, messages, location.
  2. Where it comes from — forms, sign-up, analytics, cookies, integrations.
  3. Why you collect each item — to provide the service, billing, support, analytics, marketing.
  4. Who you share it with — hosting, database, email, analytics, payment and AI providers (these are often called sub-processors).
  5. Where it is stored and processed — which countries.
  6. How long you keep it and how you delete it.
  7. How you charge — one-off, subscription, trial, refunds.
  8. Who your users are — consumers or businesses, and whether children could use it.

This list is also the most useful thing to bring to a lawyer.

What terms of service usually include

SectionWhat it coversWhy it's there
AcceptanceUsing the service means agreeing to the termsEstablishes that the terms apply
Eligibility and accountsWho can sign up, age limits, keeping login details secureSets responsibility for accounts
The serviceWhat you provide, and that it may changeManages expectations
Payments and billingPrices, billing cycles, renewals, trials, taxes, refundsPrevents billing disputes
Cancellation and terminationHow users cancel; when you can suspend or close accountsClarifies how the relationship ends
Acceptable useWhat users must not do: illegal content, abuse, spam, attacking the serviceLets you act against misuse
User contentWho owns what users upload, and the permission you need to host and display itLets you run the service without claiming their work
Intellectual propertyYou own the software and brand; users get a licence to use itProtects your product
Third-party servicesIntegrations and links you don't controlLimits responsibility for others' services
DisclaimersThe service is provided "as is", within what the law allowsSets realistic expectations
Limitation of liabilityCaps what you can be held responsible forOne of the most important and most regulated sections — get advice
Governing law and disputesWhich country's or state's law applies and where disputes goAvoids arguing about jurisdiction
Changes to the termsHow you'll notify users of changesLets you update terms fairly
ContactHow to reach youRequired or expected in many places

Consumer-protection laws in many places limit what you can put in terms for consumers — for example, how far you can exclude liability, or how automatic renewals and cancellations must work. A clause that's normal in a business contract may not hold up against a consumer. That's a key reason to get advice.

If your app uses AI

If your product generates content with AI, consider covering:

  • That outputs can be wrong and users should check them
  • Who owns the outputs (as far as your AI provider's terms allow)
  • Whether user inputs are sent to third-party AI providers
  • Acceptable-use rules for what users ask it to generate

What a privacy policy usually includes

SectionWhat it covers
Who you areBusiness name and contact details for privacy questions
Data you collectEach category, from your data map
How you collect itDirectly, automatically (cookies, logs), from third parties
Why you use itThe purposes, and under some laws the legal basis for each
SharingCategories of recipients or named providers
International transfersIf data moves between countries, and how it's protected
RetentionHow long you keep each kind of data
SecurityIn general terms, how you protect it
People's rightsAccess, correction, deletion, objection, and how to exercise them
Cookies and trackingWhat you use and how to control it — often a separate cookie policy
ChildrenWhether the service is meant for children
ChangesHow you'll tell people about updates
DateWhen it was last updated

The most important rule: it must be true. A policy that says you don't share data while your app sends it to three analytics tools is worse than a short honest one. Update the policy whenever you add a provider or start collecting something new.

For cookie banners specifically, see what are cookies and how to add cookie consent.

How to prepare a draft

  1. Complete the data and business map above.
  2. Read the terms of the providers you use — hosting, payments, email, AI. Some require you to pass on certain terms or disclosures.
  3. Start from a reputable template or generator, not another company's pages. Copying someone else's terms is a copyright problem and describes the wrong business.
  4. Edit every section so it matches what your app does. Delete what doesn't apply; add what's missing.
  5. Write plainly. Short sentences and headings help users and reduce misunderstandings.
  6. Have a lawyer review it, especially if you handle sensitive data (health, finance, children), sell to consumers in several countries, or sign contracts with larger businesses.
  7. Publish and link them in your footer, at sign-up and at checkout.
  8. Record acceptance — for example, a checkbox or clear notice at sign-up, and a note of which version each user accepted.
  9. Review them whenever your product, providers or pricing change.

Things that don't belong in legal pages

  • Promises you can't keep ("we will never have downtime").
  • Claims of compliance you haven't checked ("fully GDPR compliant").
  • Hidden terms that contradict what your pricing page says.
  • Copy-pasted sections about features you don't have.

Practical checklist

  • Data map written and matches the app
  • Every third-party provider listed or covered
  • Billing, renewal, trial and refund terms match the pricing page
  • Cancellation process described and easy
  • Contact email for legal and privacy questions works
  • Deletion requests can actually be carried out
  • Links in footer, sign-up and checkout
  • Reviewed by a lawyer
  • "Last updated" date set

Adding legal pages to an app built with Mythex

Mythex doesn't write legal documents for you, and you shouldn't rely on any AI tool for legal text without review. What it can do is the plumbing: ask the agent to add /terms and /privacy pages with your reviewed text, link them in the footer and at sign-up, add an acceptance checkbox, and store which version each user accepted in your database. A security review is also worth doing before launch — your privacy policy's promises about protecting data should be true.

Questions

Do I need a privacy policy for my app?

If your app collects any personal data — even just email addresses or analytics — privacy laws in many places expect you to explain what you collect and why, and app stores, payment providers and ad platforms often require a privacy policy too. Check the rules where you and your users are, ideally with a lawyer.

Can I copy another company's terms of service?

No. Their terms are copyrighted, and they describe their business, not yours. Terms that don't match what your app actually does can be worse than useless. Use them only to see what topics are usually covered.

Can I use a template or generator for my privacy policy?

Many small businesses start with a reputable template or generator, then edit it to match exactly what their app does. It's a starting point, not a guarantee of compliance; have a lawyer review it, especially if you handle sensitive data or sell in several countries.

What is the difference between terms of service and a privacy policy?

Terms of service set the rules between you and your users: what they can do, what you provide, payments and liability. A privacy policy explains what personal data you collect, how you use and share it, and what rights people have over it.

Keep reading

  • 20 AI Startup Ideas Where the AI Does Real Work (With MVPs) — Twenty AI startup ideas where a language model does a specific job for a specific buyer, with who pays, the MVP and the risks to plan for in each case.
  • 18 App Ideas for Small Businesses (and What to Build First) — Practical app ideas for small businesses — for customers, staff and the owner — with who each is for, why it matters, and the smallest useful version to build.
  • 20 B2B SaaS Ideas for Business Workflows (With Who Pays and the MVP) — Twenty B2B SaaS ideas built around real business workflows — sales, operations, compliance and partners — with the buyer, why they pay and the first version.
  • Bootstrapping vs Venture Capital: How to Choose — Bootstrapping vs venture capital: what each means, the trade-offs in control, speed and risk, the options in between, and questions to decide which fits you.
  • Build vs. Buy Software: A Decision Guide for Small Businesses — Should your small business build its own software or buy an existing tool? A practical decision guide with a scoring checklist, real costs and hybrid options.
  • Cold Email for Startups: A Practical Playbook with Templates — How to write cold emails that get replies: building a small target list, a four-part email structure, follow-ups, templates, and the rules to respect.

Start building free · Templates · Docs