Helping Johnny Make Sense of Privacy Policies with LLMs
Vincent Freiberger, Arthur Fleig, Erik Buchmann

TL;DR
This paper introduces PRISMe, an LLM-based browser extension that helps users understand privacy policies through summaries and interactive exploration, supported by a user study and technical improvements.
Contribution
It presents a novel interactive tool combining LLMs with retrieval-augmented generation for privacy policy analysis, along with insights from user studies.
Findings
Users appreciated clear overviews and detailed explanations.
Identified issues with adversarial robustness and hallucinations.
Retrieval-augmented generation can improve explanation reliability.
Abstract
Understanding and engaging with privacy policies is crucial for online privacy, yet these documents remain notoriously complex and difficult to navigate. We present PRISMe, an interactive browser extension that combines LLM-based policy assessment with a dashboard and customizable chat interface, enabling users to skim quick overviews or explore policy details in depth while browsing. We conduct a user study (N=22) with participants of diverse privacy knowledge to investigate how users interpret the tool's explanations and how it shapes their engagement with privacy policies, identifying distinct interaction patterns. Participants valued the clear overviews and conversational depth, but flagged some issues, particularly adversarial robustness and hallucination risks. Thus, we investigate how a retrieval-augmented generation (RAG) approach can alleviate issues by re-running the chat…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInternet Traffic Analysis and Secure E-voting · Privacy, Security, and Data Protection · Privacy-Preserving Technologies in Data
