How the score is built
Each of the 12 questions carries up to 7-9 points depending on weight. The scoring favors the answers that map to enforceable compliance: a lawyer-written policy beats a template, a tested opt-out beats an untested one, a DPA with all vendors beats partial coverage.
Failed items show up in the gap report with severity flags — fail for zero-point answers (foundational misses), warn for partial-credit answers (drift, untested processes, or unknowns). The recommended tier scales to total score:
- Below 40 · Full Coordinated SaaS/Privacy Launch Package ($2,750). Coordinated Privacy Policy + ToS or MSA + DPA + supporting terms, with a launch and compliance gap memo.
- 40-75 · Single Privacy Policy Review ($575). Targeted edits and a fix list for procedural gaps.
- Above 75 · Maintenance ($300/hr). Quarterly check-ins to catch drift as you scale.
Why I built this quiz
I'm Sergei Tokmakov, a California attorney (CA Bar #279869, licensed since 2011). The conversations I have with founders almost always start the same way: I have a privacy policy — do I need to do anything else?
The honest answer depends on twelve specific things. Rather than charge for a triage call, I built the triage. The score, the gap report, and the tier recommendation are the same ones I'd give you on a call. The Full Coordinated SaaS/Privacy Launch Package exists for the businesses where the score lands below 40: that is where the math favors a coordinated rebuild over separate reviews.
Frequently asked questions
Is the score legal advice?▾
No. This quiz is an informational tool. The score is heuristic and the gap report is a triage list, not a legal opinion. If you want privileged advice, the next step is the $575 single-document review or the $2,750 Full Coordinated SaaS/Privacy Launch Package, and I open an engagement letter at that point.
I scored 35. Do I have to start with the launch package?▾
No. The launch package is what fits a low score because it covers the documents you most likely need (Privacy Policy, Terms of Service or MSA, DPA, supporting terms) in one coordinated engagement. If budget is the constraint, start with the $575 Privacy Policy review, fix the most exposed item first, and circle back. Email me your score and stack — I'll tell you which sequencing makes sense without trying to upsell.
Why isn't my data sent anywhere?▾
The score is computed entirely in your browser. No answers leave the page unless you submit the email-capture form. If you do submit it, your email plus your answers and score come to
owner@terms.law for me to review. That's the entire data flow.
Does this work for B2B SaaS or only consumer apps?▾
Both. The DPA question (Q8) and vendor footprint (Q7) actually score B2B SaaS more carefully because B2B businesses have more exposure on the processor side. E-commerce gets weighted more heavily on payment-data sensitivity (Q5) and opt-out flow (Q9). The rubric handles both.
What's actually in the $2,750 launch package deliverable?▾
A coordinated document set plus a memo: (1) Privacy Policy, (2) Terms of Service or Master Subscription Agreement, new or substantially rebuilt, (3) Data Processing Agreement you can use with vendors and B2B customers, (4) the supporting terms the stack needs, and (5) a launch and compliance gap memo, with two consolidated revision rounds. No calls are included; scope is confirmed in writing before drafting.
Do I need a DPA if I only use Stripe and Google Analytics?▾
Both Stripe and Google have boilerplate DPAs, and accepting them is usually the right move. The gap is when you accept the boilerplate without reading the sub-processor list, the audit clause, or the transfer mechanism. The launch package includes a DPA you can use with vendors and B2B customers, not just a signature on theirs.
Is GPC really mandatory?▾
In California, yes — CPRA requires businesses to honor opt-out preference signals, and GPC is the recognized signal. Other states (Colorado, Connecticut) are adopting similar rules. The technical implementation is usually a one-time engineering task; the legal exposure of ignoring it is ongoing.
What if I don't have any EU customers but use Mailchimp?▾
If your platform stores any data on EU servers (most major SaaS does), you may still need transfer mechanisms in your vendor contracts even though your customers are US-only. The DPA review is the place to catch this.
Disclaimer. This calculator is an informational tool authored by Sergei Tokmakov, a California-licensed attorney (CA Bar #279869). It is not legal advice and does not create an attorney-client relationship. The composite score and gap report are heuristic estimates based on a fixed set of factors — they do not substitute for review of your actual policies, vendor contracts, and use case. Privacy laws vary by jurisdiction and change frequently. For advice on a specific matter, email
owner@terms.law.