by PrivScan (LX AI)
A privacy-policy gap is any place where your published notice does not match what the product actually does with personal data. AI features create gaps quickly, because they add collection points that a template written before the feature existed never mentions.
Key takeaways
Walk the product the way a user would and write down every place personal data enters it. Compare that list against the notice line by line. Where the notice is silent, add the category, the purpose and the retention. Where the notice is vague, name the category instead.
PrivScan scans the site or app for the consumer-privacy gaps above — cookies, consent, trackers and data collection — and returns them as a prioritised checklist, so the gap between what the product does and what the notice says becomes a work queue rather than a guess.
It can be. If the prompt can be linked to an identified or identifiable person, it falls in scope and needs to be covered by the notice.
Recipients of personal data are normally disclosed. Naming the provider, or at least the category and location, is the safer disclosure.
If user content is used to train or improve a model, say so plainly. Silence on that point is one of the most-read lines of any AI privacy notice.
On every material change to what you collect or which providers you use — for AI products, that is usually more often than once a year.
No. It reports the gaps it can detect from the site and your description. Drafting the disclosure still needs a human.
No. It is a decision-support checklist, and a reviewer still has to confirm the facts.
Try the product: PrivScan