Methodology

PrivacyLens turns a privacy policy into a structured dossier using Google's Gemini model, guided by a fixed schema and a set of rules aimed at keeping every finding traceable back to the source text.

What PrivacyLens analyzes

  • Data categories collected and their stated purposes
  • Third-party recipient categories and what data may reach them
  • Retention principles and any category-specific periods
  • Rights and controls the policy itself describes, and whether they read as global or region-specific
  • Advertising, profiling, and automated decision-making, where addressed
  • A fixed clarity audit across seven topics, plus any other open questions

What it does not do

  • Independently verify a company's actual data practices
  • Determine legal compliance with any law or regulation
  • Guarantee completeness — a policy can omit things this tool won't know to ask about
  • Provide legal advice, or calculate an overall "privacy score"

How an analysis runs

  1. Extract the policy text (from a pasted excerpt or a fetched URL)
  2. Identify the data categories it discusses
  3. Map the stated purpose for each category
  4. Identify third-party recipient categories
  5. Identify retention statements — general principle and any category-specific periods
  6. Identify rights or controls the policy itself describes
  7. Run a fixed seven-category clarity audit
  8. Flag genuine open questions that don't fit the audit categories
  9. Attach a short evidence excerpt to every finding
  10. Assign a confidence level to every finding

Review priority

Review priority tells you where to look first — it is not a judgment of the company. It's assigned from the policy text using a fixed rule, before any AI-written summary is added: High • Highly identifying data (name, government ID, precise location) • Financial information • Sensitive account credentials • Data the policy says is shared with third parties or used for advertising/profiling with few stated limits Medium • Device or technical information • Usage/behavioral information • User-generated content Low • Categories where the policy provides little or no specific collection information "High" means "review this first," not "this company is doing something wrong." PrivacyLens does not calculate an overall privacy score or rank companies.

Evidence confidence

Evidence confidence is a different concept from review priority — it's about how directly the policy text supports a finding, not how sensitive the data is: High confidence — the finding is directly supported by explicit policy language, shown in the evidence excerpt. Medium confidence — supported by related but less direct language, or inferred by combining more than one statement in the policy. Low confidence — only indirectly suggested by general or vague language. A "high confidence" label means the text clearly says this — it does not mean PrivacyLens has verified it against the company's actual practices.

Policy evidence excerpts are short quotations from the text you provided, shown separately from PrivacyLens's own analysis so the two are never mistaken for each other. Everything on this page describes the current version of the tool and may change as it develops.