Skip to content
Back to skills

Privacy

ASecurity

Privacy and data protection - GDPR, CCPA, consent. Use when handling user data.

  • 16 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added June 8, 2026
ai-agentsrustgogit

Security analysis

A100/100

Scanned June 8, 2026

npx -y skills add ThomasMoreAI/legal-skills-open --skill privacy --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Privacy?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Privacy
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/thomasmoreai-privacy/badge)](https://www.skillsdirectory.com/skills/thomasmoreai-privacy)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: privacy
title: Privacy Guideline
description: Privacy and data protection - GDPR, CCPA, consent. Use when handling user data.
author: SylphxAI
author_url: https://github.com/SylphxAI/flow/tree/main/packages/flow/assets/skills/privacy
license: MIT
version: 0.1.0
execution_mode: open
jurisdiction: general
practice: data-protection
language: en
---

# Privacy Guideline

## Tech Stack

* **Analytics**: PostHog
* **Email**: Resend
* **Tag Management**: GTM (marketing only)
* **Observability**: Sentry

## Non-Negotiables

* Analytics and marketing must not fire before user consent
* PII must not leak into logs, Sentry, PostHog, or third-party services
* Account deletion must propagate to all third-party processors
* Marketing tags (GTM, Google Ads) must not load without consent
* Conversion tracking must be server-truth aligned, idempotent, and deduplicated

## Context

Privacy isn't just compliance — it's trust. Users share data expecting it to be handled responsibly. Every log line, every analytics event, every third-party integration is a potential privacy leak.

The review should verify that actual behavior matches stated policy. If the privacy policy says "we don't track without consent," does the code actually enforce that? Mismatches are not just bugs — they're trust violations.

## Driving Questions

* Does the consent implementation actually block tracking, or just record preference?
* Where does PII leak that we haven't noticed?
* If a user requests data deletion, what actually gets deleted vs. retained?
* Does the privacy policy accurately reflect what the code actually does?
* How would we handle a GDPR data subject access request today?
* What data are we collecting that we don't actually need?

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…