# Privacy policy and terms

Before a solo developer or freelancer shows a service to the world or submits an app for review, they need a privacy
policy and usually terms of use. heremyapp agents create them from templates, publish them at `/privacy` and `/terms`,
and link them from every page, so the user does not have to remember.

## Do you need them?

Default: **create both**, and keep them short when the app is simple.

| Page | When | Why |
|---|---|---|
| Privacy policy (`/privacy`) | Always for apps in the App Store or Google Play; any site or app that collects personal information (forms, accounts, emails, analytics, crash reports, cookies) | Apple requires a privacy policy URL for every app; Google Play asks for one in the Data safety section; privacy laws (GDPR, CCPA, South Korea's PIPA) require one when personal information is processed. Even "we collect nothing" is worth stating. |
| Terms of use (`/terms`) | Accounts, payments, user content or an online service; recommended for free apps as a license and disclaimer | Sets the license, limits liability, and answers reviewers and customers |

## How agents create them

1. Find out what the app and site really do with data: read the code for network requests, analytics or
   crash-reporting SDKs, accounts, payments, permissions and the files it reads. Do not guess.
2. Fetch the templates and fill them in:

```bash
curl -fsSL https://heremyapp.com/docs/templates/privacy.md
curl -fsSL https://heremyapp.com/docs/templates/terms.md
```

3. Take the operator name and contact email from the space's contact details
   ([Landing page checklist](https://heremyapp.com/docs/landing.md)). If they are unknown, ask for them in the same single contact question.
   A privacy policy needs a way to reach the operator; if the user skips, use the support page or ask whether a contact
   form or email can be added.
4. Publish them as `privacy.html` and `terms.html` at the site root (served at `/privacy` and `/terms`), styled like the
   rest of the site. With multiple languages, add `ko/privacy.html` and so on; the Korean privacy policy should follow
   the headings noted at the end of the privacy template.
5. Link both from **every page**, in the footer (and optionally the header): "Privacy" and "Terms" in the page's language.
6. Tell the user which facts you assumed and that the documents are templates, not legal advice. Suggest a review by a
   professional if the service takes payments or handles sensitive data.

Adding the legal pages is a `minor` release. When you change them later, update the effective date.

## App store and review fields

Use the permanent public URLs. They keep working when heremyapp moves sites to a new domain.

| Field | URL |
|---|---|
| App Store Connect: Privacy Policy URL; Google Play: Privacy policy | `https://heremyapp.com/ACCOUNT/SPACE/privacy` |
| Terms of use or EULA link (if the store asks) | `https://heremyapp.com/ACCOUNT/SPACE/terms` |
| Support URL | `https://heremyapp.com/ACCOUNT/SPACE` with a contact section, or a support page |
| Marketing URL | `https://heremyapp.com/ACCOUNT/SPACE` |

What the policy says must match the store's privacy questionnaire (Apple's App Privacy details, Google Play's Data
safety form).

## Deploy advice

Every deploy response has an `advice` list that never blocks the deploy. It reports `missing_privacy`,
`missing_terms` and `legal_not_linked`, as well as landing page basics (`missing_link_preview`, `og_image_not_absolute`,
`missing_lang`, `missing_description`, `missing_favicon`). Each item has a `message` and a `docs` link. Fix what applies
and deploy again; an empty list means the checks passed.
