C. Website Launch Readiness · Prompt 28
Legal & Trust Pages
Get the free PDFWhy it matters
A missing age check, a font loaded from a third party, or a marketing email with no unsubscribe can create legal exposure before the first sale. This is a checklist for a lawyer, not legal advice.
Modeled on
Privacy-by-design practice, the US rules named below, and India's Digital Personal Data Protection Act, 2023. This is a technical checklist, not legal advice.
How to run this prompt
- Switch to a mode that does not edit files. In Cursor that is Ask or Plan. In Claude Code that is Plan mode.
- Paste the audit prompt. Wait for the report. It must stop and ask which IDs to fix.
- Read the report. Keep the IDs you agree with.
- Switch to a mode that can edit. Paste the fix prompt and the IDs you chose.
- Switch back to the read-only mode and paste the same audit prompt again. Confirm those IDs are gone.
- Cursor: audit in Ask mode or Plan mode. Fix in Agent mode.
- Claude Code: audit in Plan mode (Shift+Tab cycles to it). Fix in Normal mode, which can edit.
- Any other tool: audit in Chat, Discuss, or Plan mode, whichever answers without editing files. If the tool has no such mode, the prompt itself forbids edits. Fix in the mode that is allowed to edit files.
The audit prompt
MODE: AUDIT ONLY. Do not create, edit, or delete any file. Do not run commands
that change anything: no installs, migrations, git commits, deploys, or "--fix" flags.
If your tool has an Ask, Plan, Chat, or Discuss mode, use it for this prompt.
Before you start:
- Tell me the stack you detect (framework, language, database, auth, hosting,
payment provider) and which folders you will review.
- If a check below does not apply to this stack, write "Not applicable" and why.
- If you can run read-only commands, run the ones listed. If you cannot, list them
so I can run them and paste the output.
Legal & Trust Pages: what to check
Prepare notes for legal pages and pre-launch legal gaps based on what this repo actually does. I will have a lawyer review them. Do not present the result as legal advice. Do not invent a company name, address, refund policy, or a fine amount. Flag the gap. Do not predict a lawsuit.
1. List what the site collects and where it goes: forms, accounts, payments, cookies, analytics, third-party scripts, and embedded videos. Base every later point on that list.
2. Draft a privacy policy outline from that list: what is collected, why, who receives it, how long it is kept if the code or docs say so, how a person can ask for access or deletion, and how to contact the owner. If retention is not in the repo, write "ask the owner" instead of a number.
3. Draft terms headings that match the product: accounts, purchases, refunds, acceptable use, liability, and a governing-law placeholder. Mark every placeholder.
4. Say whether a cookie banner is needed. GDPR in the EU and UK, India's DPDP Act 2023, and the California CCPA/CPRA are examples that depend on where users are. Do not decide that a banner is required. If analytics or non-essential cookies load before consent, say that a banner which does not block those scripts would be misleading.
5. Check the contact block uses a real email and address from the project config. Flag placeholders such as example.com.
6. Check the footer and every data-collection form link to the privacy page.
7. End with questions for a lawyer: jurisdiction, retention, and whether a banner is required for this audience.
8. Do not publish the drafts as final policy text.
9. Age on signup. If the product is directed at children, or the app can know a user is under 13, look for an age gate or date of birth before the account is created. The US COPPA rule can apply in those cases. The FTC publishes an inflation-adjusted civil penalty per violation. Do not say that every signup without an age field is a violation.
10. Fonts loaded from Google. Search for fonts.googleapis.com and fonts.gstatic.com. A Munich court (LG München I, 20 January 2022) awarded a small sum in one case where a visitor's IP was sent to Google. The check is whether fonts are self-hosted. If fonts are bundled by the framework, write "Not applicable" and name the file.
11. Session replay. Look for Hotjar, FullStory, Microsoft Clarity, LogRocket, or PostHog session recording that starts without consent or records keystrokes and form fields. Plaintiffs use California's Invasion of Privacy Act, which has a statutory amount per violation. Consent plus masking of inputs is the mitigation. Do not call every analytics script wiretapping.
12. Marketing email. In templates for a launch or promo email, require an unsubscribe link and a real postal address. CAN-SPAM applies to commercial email. A receipt or a password reset is a different case. The FTC's per-email ceiling is inflation-adjusted, so name the rule and say to look up the current figure. Do not invent the dollar amount.
13. Subscription checkout. If the app sells a renewal, the price, the renewal interval, and how to cancel must sit next to the subscribe button, not only in a terms page. California's automatic-renewal statute can treat non-compliant charges as refundable. If there is no subscription, write "Not applicable".
14. User uploads and a DMCA agent. If users can upload images or other content, look for a copyright policy and a designated agent registered with the US Copyright Office. The registration fee is 6 US dollars. Missing an agent can remove the hosting safe harbor. Statutory damages for infringement can be large. They are not an automatic fine for skipping that filing. If the app has no user uploads, write "Not applicable".
15. DPDP notice and consent. India's Digital Personal Data Protection Act, 2023 can apply when personal data is processed in India, or outside India while offering goods or services to people in India. Do not mix this with COPPA or GDPR. Before or at collection, look for a notice that says what personal data is collected and why, and for consent that is an explicit opt-in. A pre-ticked box, or "by using this site you agree", is not that consent. Withdrawal must be as easy as giving consent.
16. DPDP rights and grievance contact. Look for a way to access, correct, and erase personal data, and a real contact for grievances. Do not require a Data Protection Officer unless the app is, or might be, a Significant Data Fiduciary. The government notifies who those are. Do not guess that this app is one.
17. DPDP and children. COPPA's age is 13. DPDP's age is 18. If a child can use the product, look for verifiable consent of a parent or guardian, and for tracking, behavioural monitoring, or targeted advertising aimed at children. Flag those as gaps.
18. DPDP security and breaches. Look for a stated security safeguard and a path to tell the Data Protection Board and the affected person about a personal-data breach. The Act's Schedule sets ceilings, including up to 250 crore rupees for failing reasonable security safeguards and up to 200 crore rupees for children's-data or breach-notice failures. Those are ceilings, not automatic fines. Do not calculate a penalty.
19. DPDP cross-border transfer. Transfer is allowed unless the government has restricted the destination country. Do not apply GDPR's adequacy test to an Indian user base.
20. DPDP rules and dates. Check whether the DPDP Rules are in force for that duty. Do not assume every section is already enforceable. Still mark a missing notice or consent as a gap to fix.
Evidence rules:
- Every finding cites a file path and line number, or the exact command output used.
- Mark each finding Confirmed (seen in the code) or Needs manual check (depends on
something outside the repo, such as a dashboard setting or production data).
- Never print a full secret. Show the first 4 characters and the location only.
- If you are not sure, say so. Do not invent files, settings, or results.
Severity: Critical = exploitable now, or leaks real data or money. High = serious
with little effort. Medium = weakens defenses or needs a second bug. Low = hygiene.
Report:
- Summary: count of findings by severity.
- Table: ID | Severity | Confirmed? | Finding | Evidence | Why it matters | Suggested fix | Effort
(IDs for this prompt use the prefix P28, for example P28-1, P28-2.)
- Checked and fine: what you verified is already OK.
- Could not check: what I need to look at myself, and where.
Then stop. Do not fix anything. Ask me which IDs I want fixed.