Inspiration
Privacy policies are everywhere, but most people do not have the time or legal expertise to read and understand lengthy documents filled with complex language. Important details about what data is collected, who it is shared with, how long it is retained, and what users can do with their data are often buried deep inside.
We were inspired to build PrivacyLens to make privacy policies easier to understand and more actionable. Instead of simply summarizing a policy, we wanted to create a tool that helps users quickly see what is happening to their data, what is unclear, and what actions they can take.
What it does
PrivacyLens transforms lengthy privacy policies into a structured, easy-to-understand privacy dossier.
It identifies:
- What types of personal data are collected and why
- Who the data may be shared with
- How long different types of data are retained
- Areas where the policy is unclear or incomplete
- Privacy rights and available actions
- Relevant jurisdiction-specific privacy options
PrivacyLens also provides the original policy evidence behind its analysis, helping users distinguish between what the policy explicitly states and what the analysis means for them. Users can also generate a draft privacy request based on the rights and issues identified.
How we built it
We built PrivacyLens as a modern web application using Next.js, React, TypeScript, and Tailwind CSS. We use AI powered analysis to process privacy-policy text and extract relevant information such as data categories, purposes, recipients, retention periods, rights, and ambiguities.
The extracted information is organized into a structured interactive interface with summary cards, data-to-purpose mappings, recipient mappings, retention analysis, clarity audits, policy evidence, and actionable privacy-rights sections.
We also designed the system to keep AI analysis separate from the underlying policy evidence, so users can inspect the source text behind important conclusions instead of having to blindly trust an AI generated summary.
Challenges we ran into
One of our biggest challenges was making sure PrivacyLens did more than simply generate a generic AI summary. Privacy policies contain nuanced language, conditional statements, exceptions, and information spread across different sections, so extracting useful information while preserving context was challenging.
Another challenge was distinguishing between what a policy explicitly states and what can reasonably be inferred from it. We addressed this by presenting the analysis separately from the supporting policy evidence and highlighting open questions instead of pretending that missing information was known.
We also had to balance a large amount of information with a clean and understandable interface. The final design uses structured sections, summaries, navigation, expandable evidence, and clarity indicators to make a long analysis easier to explore.
Accomplishments that we're proud of
We are proud that PrivacyLens goes beyond simply summarizing a privacy policy and turns it into an actionable privacy analysis.
Some of the features we are particularly proud of include:
- Structured identification of personal data categories
- Data-to-purpose and data-to-recipient mappings
- Retention-period analysis
- Explicit identification of open questions and ambiguities
- Evidence-backed AI analysis
- Jurisdiction-aware privacy rights information
- An interactive privacy rights request generator
- A clear, document style interface designed for easy navigation
Most importantly, we built the project around the idea that users should be able to understand why an insight was produced and trace it back to the policy evidence.
What we learned
We learned that building a useful AI application is not just about generating accurate text. The way information is structured, explained, and connected to its source is equally important.
We learned how to combine AI powered document analysis with a structured data model and an interactive frontend. We also learned the importance of handling uncertainty explicitly rather than presenting incomplete information as fact.
PrivacyLens also taught us how to design for transparency and user control, especially when working with sensitive topics such as personal data and privacy rights.
What's next for PrivacyLens
We want to continue developing PrivacyLens into a more comprehensive privacy assistant.
Future improvements could include comparing privacy policies across different companies, tracking changes between policy versions, allowing users to save and monitor policies, expanding support for more jurisdictions, and improving the accuracy of policy analysis through stronger evidence extraction and validation.
Our long term goal is to make understanding digital privacy as simple as checking a few key insights, while still allowing users to explore the underlying evidence when they want more detail.
Built With
- generative-ai
- llm
- natural-language-processing
- next.js
- react
- rest-api
- tailwind
- typescript
- vercel
Log in or sign up for Devpost to join the conversation.