Ali Zamanian Startup Legal Strategy
AI, Data & Contracts7 min read

Does your startup need a privacy policy? Yes, and sooner than you think.

Founders treat the privacy policy and terms of service as launch-week paperwork. In practice, four separate forces make them mandatory early: state privacy laws, GDPR's activity-based reach, the platforms you depend on, and deception liability for saying things that are not true. Here is what each document actually has to do.

Here is the direct answer: if your product collects any personal information, and nearly every product does, you need a privacy policy now, not at some future milestone. The terms of service follow close behind, because they are the contract that limits your liability and defines who owns what. Founders postpone both because no customer is asking yet. The problem is that the four forces that make these documents mandatory do not wait for customers to ask.

This guide explains the four forces, what each document actually has to contain, where templates quietly fail, and the moment this stops being hygiene and starts deciding deals. It pairs with the broader AI startup legal checklist and the enterprise sales checklist where these documents get read by procurement.

The four forces that make the answer yes

1. State privacy laws reach further down than founders assume. California's CalOPPA has required a conspicuously posted privacy policy for websites and apps collecting personal information from California residents since long before the CCPA existed, and it has no revenue threshold worth relying on. The CCPA, as amended, applies to for-profit businesses doing business in California that cross thresholds such as roughly $26.6 million in annual gross revenue (the figure is inflation-adjusted) or the personal information of 100,000 or more California consumers or households. A seed-stage company may sit below the CCPA line, but a dozen other states now run comparable comprehensive privacy laws with their own thresholds, and they do not coordinate their math for your convenience.

2. GDPR does not care how small you are. The European regime is activity-based, not size-based. If you offer your service to people in the EU or monitor their behavior, you are in scope, whether you are a two-person company in Austin or a public company. The obligations start with transparency, which in practice means a privacy notice that accurately describes your processing, its legal bases, retention, and user rights. US founders regularly discover GDPR through their first EU customer's vendor questionnaire rather than through their own planning.

3. The platforms you depend on require it by contract. Apple and Google require privacy policies and privacy disclosures for apps. Payment processors, ad networks, and analytics providers require policy language covering their data flows. OAuth providers require published policies before granting production API access. These are contractual gates: no policy, no distribution.

4. Saying something false is worse than saying nothing. The FTC treats material misstatements in privacy policies as deceptive practices under Section 5, and state attorneys general have equivalent tools. This is the trap inside every copied template: the generic policy promises practices that are not yours, and each false promise is potential liability you created yourself.

What the privacy policy actually has to do

A privacy policy is a disclosure document, and it can only be written accurately from a data inventory: what you collect, from whom, why, where it goes, how long you keep it, and who you share it with. From that inventory, the policy should cover, in plain language:

For AI products there is one addition that now gets read closely: whether customer inputs and outputs are used to train or improve models, by you or by your upstream providers. Enterprise buyers scan for that sentence before anything else, which is why it belongs in your model-provider terms review as much as in your policy.

A privacy policy is not marketing copy. It is a set of promises regulators can hold you to. Write the promises you actually keep.

What the terms of service actually have to do

The terms of service are not a disclosure; they are a contract, and their job is allocation. Done well, they quietly answer the questions that otherwise become disputes:

Self-serve products live on click-through acceptance, so the terms must be presented so that acceptance is real: a clear affirmative act at signup, records of versions, and notice on material changes.

The template question, answered honestly

Generators and templates are fine as scaffolding and dangerous as final answers, for one reason: they do not know your data practices. The failure pattern is predictable. The template says you do not sell data, but your ad SDK's data sharing may qualify as a sale under state law definitions. The template says you delete on request, but nothing in your stack actually deletes. The template is silent on training data, and your model provider's default terms say otherwise. Every one of those gaps is a misrepresentation you published about yourself. Start from a template if you like, then make each sentence true, and have the result reviewed once by someone qualified. That single pass is cheap relative to what it prevents.

The B2B angle founders miss

Founders selling to businesses often assume privacy is a consumer problem. It is not. Your enterprise customer's employees and end users are data subjects, and when that customer pushes EU or California personal data through your platform, you are a processor or service provider, and they will hand you a data processing agreement to sign. Having your own DPA ready, consistent with your privacy policy and your subprocessor list, is the difference between a two-day procurement step and a three-week one. This is exactly the terrain of the enterprise AI sales checklist, and if EU users are in the picture, the EU AI Act analysis sits next to it.

// what to take from this
  • If you collect personal information, you need a privacy policy now: CalOPPA, GDPR's activity-based reach, platform requirements, and deception liability all point the same way.
  • CCPA-style thresholds (roughly $26.6M revenue or 100k consumers, adjusted over time) exempt many early startups; GDPR has no size threshold at all.
  • Write the policy from a data inventory; a policy that misdescribes your practices is worse than none.
  • Terms of service are your liability architecture: license, ownership (including AI inputs and outputs), caps, termination, disputes.
  • Selling B2B makes you a processor: have a DPA and subprocessor list ready before procurement asks.

The pattern across all of it: these documents are cheap when they are honest and early, and expensive when they are copied and wrong. Write them from what your product actually does, review them when the product changes, and they become an asset that speeds up deals instead of a liability wearing a legal costume.

Related reading: the AI startup legal checklist, AI vendor and model-provider terms, and US state AI laws in 2026. For the B2B contract behind all of this, read what a DPA is and when you need one. Or start a conversation about your data practices and paper.

This article is general information for founders. It is not legal advice, and reading it does not create a professional relationship. Privacy obligations depend on what data you collect, where your users are, and laws that change frequently, including inflation-adjusted thresholds and new state statutes. Confirm your obligations with a qualified attorney before relying on any of this.

Ali Zamanian

Startup Legal Strategy

Ali writes for founders and growing technology companies on equity, formation, contracts, IP, AI governance, and startup legal strategy. The work is built around a business-first lens: protect the upside, build leverage, and keep the paper trail clean.

Shipping a product that touches user data? Get the paper right.

A focused first conversation on your data practices, the privacy policy and terms your product actually needs, and the gaps an enterprise customer or investor will find.

Start a conversation