How to Write Terms of Service and a Privacy Policy for Your App
What terms of service and a privacy policy for your app usually contain, why each section matters, how to prepare a draft, and when to involve a lawyer.
Mythex Team · · 6 min read
This guide is not legal advice. It explains what terms of service and a privacy policy usually contain and why, so you can prepare a sensible draft and have a better conversation with a lawyer. The rules that apply to you depend on where your business is, where your users are, what data you collect and what you sell. For anything beyond a small, low-risk app — and ideally for that too — have a qualified lawyer review your documents.
The short version: your terms of service set the rules between you and your users. Your privacy policy explains, honestly, what personal data you collect and what you do with it. Both must describe what your app actually does.
Why these documents matter
- Privacy laws. Many countries and regions have laws that require you to tell people what personal data you collect and why — the EU's GDPR is the best-known example (see what is GDPR).
- Third parties require them. App stores, payment providers, ad platforms and login providers such as "Sign in with Google" commonly ask for a link to your privacy policy and sometimes your terms.
- Disputes. Clear terms about payments, refunds and acceptable use make disagreements easier to resolve.
- Trust. Customers, especially businesses, read these pages before they buy.
Before you write: map your data and business
You can't describe what you don't know. Write down:
- What personal data you collect — names, emails, payment details (usually handled by your payment provider), IP addresses, usage data, uploaded files, messages, location.
- Where it comes from — forms, sign-up, analytics, cookies, integrations.
- Why you collect each item — to provide the service, billing, support, analytics, marketing.
- Who you share it with — hosting, database, email, analytics, payment and AI providers (these are often called sub-processors).
- Where it is stored and processed — which countries.
- How long you keep it and how you delete it.
- How you charge — one-off, subscription, trial, refunds.
- Who your users are — consumers or businesses, and whether children could use it.
This list is also the most useful thing to bring to a lawyer.
What terms of service usually include
| Section | What it covers | Why it's there |
|---|---|---|
| Acceptance | Using the service means agreeing to the terms | Establishes that the terms apply |
| Eligibility and accounts | Who can sign up, age limits, keeping login details secure | Sets responsibility for accounts |
| The service | What you provide, and that it may change | Manages expectations |
| Payments and billing | Prices, billing cycles, renewals, trials, taxes, refunds | Prevents billing disputes |
| Cancellation and termination | How users cancel; when you can suspend or close accounts | Clarifies how the relationship ends |
| Acceptable use | What users must not do: illegal content, abuse, spam, attacking the service | Lets you act against misuse |
| User content | Who owns what users upload, and the permission you need to host and display it | Lets you run the service without claiming their work |
| Intellectual property | You own the software and brand; users get a licence to use it | Protects your product |
| Third-party services | Integrations and links you don't control | Limits responsibility for others' services |
| Disclaimers | The service is provided "as is", within what the law allows | Sets realistic expectations |
| Limitation of liability | Caps what you can be held responsible for | One of the most important and most regulated sections — get advice |
| Governing law and disputes | Which country's or state's law applies and where disputes go | Avoids arguing about jurisdiction |
| Changes to the terms | How you'll notify users of changes | Lets you update terms fairly |
| Contact | How to reach you | Required or expected in many places |
Consumer-protection laws in many places limit what you can put in terms for consumers — for example, how far you can exclude liability, or how automatic renewals and cancellations must work. A clause that's normal in a business contract may not hold up against a consumer. That's a key reason to get advice.
If your app uses AI
If your product generates content with AI, consider covering:
- That outputs can be wrong and users should check them
- Who owns the outputs (as far as your AI provider's terms allow)
- Whether user inputs are sent to third-party AI providers
- Acceptable-use rules for what users ask it to generate
What a privacy policy usually includes
| Section | What it covers |
|---|---|
| Who you are | Business name and contact details for privacy questions |
| Data you collect | Each category, from your data map |
| How you collect it | Directly, automatically (cookies, logs), from third parties |
| Why you use it | The purposes, and under some laws the legal basis for each |
| Sharing | Categories of recipients or named providers |
| International transfers | If data moves between countries, and how it's protected |
| Retention | How long you keep each kind of data |
| Security | In general terms, how you protect it |
| People's rights | Access, correction, deletion, objection, and how to exercise them |
| Cookies and tracking | What you use and how to control it — often a separate cookie policy |
| Children | Whether the service is meant for children |
| Changes | How you'll tell people about updates |
| Date | When it was last updated |
The most important rule: it must be true. A policy that says you don't share data while your app sends it to three analytics tools is worse than a short honest one. Update the policy whenever you add a provider or start collecting something new.
For cookie banners specifically, see what are cookies and how to add cookie consent.
How to prepare a draft
- Complete the data and business map above.
- Read the terms of the providers you use — hosting, payments, email, AI. Some require you to pass on certain terms or disclosures.
- Start from a reputable template or generator, not another company's pages. Copying someone else's terms is a copyright problem and describes the wrong business.
- Edit every section so it matches what your app does. Delete what doesn't apply; add what's missing.
- Write plainly. Short sentences and headings help users and reduce misunderstandings.
- Have a lawyer review it, especially if you handle sensitive data (health, finance, children), sell to consumers in several countries, or sign contracts with larger businesses.
- Publish and link them in your footer, at sign-up and at checkout.
- Record acceptance — for example, a checkbox or clear notice at sign-up, and a note of which version each user accepted.
- Review them whenever your product, providers or pricing change.
Things that don't belong in legal pages
- Promises you can't keep ("we will never have downtime").
- Claims of compliance you haven't checked ("fully GDPR compliant").
- Hidden terms that contradict what your pricing page says.
- Copy-pasted sections about features you don't have.
Practical checklist
- Data map written and matches the app
- Every third-party provider listed or covered
- Billing, renewal, trial and refund terms match the pricing page
- Cancellation process described and easy
- Contact email for legal and privacy questions works
- Deletion requests can actually be carried out
- Links in footer, sign-up and checkout
- Reviewed by a lawyer
- "Last updated" date set
Adding legal pages to an app built with Mythex
Mythex doesn't write legal documents for you, and you shouldn't rely on any AI tool for legal text without review. What it can do is the plumbing: ask the agent to add /terms and /privacy pages with your reviewed text, link them in the footer and at sign-up, add an acceptance checkbox, and store which version each user accepted in your database. A security review is also worth doing before launch — your privacy policy's promises about protecting data should be true.
Questions
Do I need a privacy policy for my app?
If your app collects any personal data — even just email addresses or analytics — privacy laws in many places expect you to explain what you collect and why, and app stores, payment providers and ad platforms often require a privacy policy too. Check the rules where you and your users are, ideally with a lawyer.
Can I copy another company's terms of service?
No. Their terms are copyrighted, and they describe their business, not yours. Terms that don't match what your app actually does can be worse than useless. Use them only to see what topics are usually covered.
Can I use a template or generator for my privacy policy?
Many small businesses start with a reputable template or generator, then edit it to match exactly what their app does. It's a starting point, not a guarantee of compliance; have a lawyer review it, especially if you handle sensitive data or sell in several countries.
What is the difference between terms of service and a privacy policy?
Terms of service set the rules between you and your users: what they can do, what you provide, payments and liability. A privacy policy explains what personal data you collect, how you use and share it, and what rights people have over it.