← All posts

How to write a privacy policy your clients will actually read.

Most privacy policies are legal disclaimers no one reads. Here's how to write one that actually communicates—and why that matters for the communities you serve.

Most privacy policies are not written to be read. They’re written to provide legal documentation that certain disclosures were made, drafted by a lawyer or copied from a template, dropped into the footer, and forgotten. Nobody expects anyone to read them, because they’re not written for reading.

This is a problem in general. It’s a specific problem for organizations serving people who have real stakes in understanding how their information is handled—domestic violence survivors, immigrants, people seeking reproductive healthcare, LGBTQ+ youth. These are people for whom the question “what does this organization do with my information?” is not abstract. They need a real answer, in language they can understand, available before they decide whether to engage with your services.

A plain-language privacy policy isn’t just a nice-to-have. For some of your clients, it’s the basis on which they decide whether they can trust you.

What a plain-language privacy policy actually covers

The goal isn’t to replace legal language with nothing—it’s to add a plain-language translation that gives people the information they actually need. Some policies do both: a plain-language summary followed by more detailed language for those who want it. Others translate the whole thing. Either approach is better than boilerplate nobody reads.

Here’s what your privacy policy should cover:

What you collect. Be specific. Not “we may collect personal information including but not limited to”—that’s not information. Something like: “When you contact us through our website form, we collect your name, email address, and the content of your message. We don’t collect anything else unless you share it voluntarily.”

Why you collect it. “We collect your email address to respond to your inquiry and, if you check the box, to send you our newsletter. We don’t use it for any other purpose.” That’s a sentence. It answers the question.

Who sees it. Name the categories of people and systems that have access to the information you collect. “Your form submission goes to our intake coordinator. It’s also stored in [platform name]’s system, which we use to manage our contacts. We don’t share it with any other organizations or individuals.” If you use third-party tools that have access to client data, name them. If your case management platform is shared with partner organizations, say so.

How long you keep it. “We keep contact form submissions for 90 days and then delete them unless you’ve become an active client, in which case your information is kept according to our records retention policy.” This sentence tells people something useful. Most privacy policies say nothing equivalent.

Whether you use tracking tools. If you’re running Google Analytics, say so and explain what it does. If you’ve removed social media pixels, say that too—it’s a positive thing to communicate. If you use a cookie banner, your privacy policy should explain what the cookies do.

What people can ask you to do. Most people don’t know they have rights around their personal data. Your privacy policy should tell them: they can ask you to delete their information, ask what you have on file, and ask you to correct errors. And it should tell them how to do that—an email address, not just “contact us.”

What you don’t do. This is underused. If you don’t sell data, say so. If you’ve chosen not to run Facebook pixels because you serve vulnerable populations, say so and explain why. If you don’t share client information with law enforcement except when legally required, say so. The things you don’t do are sometimes the most important disclosures you can make for your client base.

How to handle the mandatory reporting question

For organizations with mandatory reporting obligations—most healthcare providers, some social service organizations—the privacy policy is one of the places to address this directly. People who are sharing sensitive information deserve to know before they share it whether there are circumstances under which that information might be disclosed without their consent.

This doesn’t have to be complicated: “As required by Connecticut law, our staff may be legally required to report certain information to state authorities in specific circumstances, including suspected child abuse or neglect. Outside of mandatory reporting requirements, we do not share your information without your consent.”

Clear, plain, accurate. It’s not a comfortable thing to include, but clients who receive that disclosure before sharing information have been given the opportunity to make an informed decision. That’s the point.

Format and findability

A privacy policy that’s technically available but practically impossible to find is not serving its function. It should be linked from every page of your site—typically in the footer—and the link should be labeled “Privacy Policy,” not buried under “Legal” or hidden in a terms of service umbrella link.

It should also be formatted for reading, not for archiving. Headers that organize the content logically. Short paragraphs. Plain language throughout. If you have a longer legal version, consider leading with a plain-language summary—a few sentences per section that tell the reader what they need to know—and presenting the detailed language below it.

The test is simple: give your privacy policy to someone who doesn’t work at your organization and ask them if they understand what you do with their information. If they can answer that question, your policy is working. If they can’t, it isn’t—regardless of whether it’s legally compliant.

If you’d like help drafting or revising your privacy policy in plain language, that’s something I’m happy to work on with you.