Footer policy audit, all 26 live sites
Private deliverable. Enter the hub password to continue.
That's not right. Try again.
Footer policy audit, all 26 live sites
I fetched every live site, read its footer, and checked whether the policy pages it links to actually exist. Two sites are complete. One is making a promise it cannot keep.
I checked every property that actually serves a page: the 23 Cloudflare Pages sites on your custom domains, socialmapped.com on its Worker, rebuildingseminars.com on GoHighLevel, and exercisebuddyfinder.com, which is live but missing from your site registry. The 11 parked domains that serve nothing were excluded on purpose.
For each one I pulled the homepage, isolated the footer, classified every link in it, then requested each policy URL to confirm the page is real rather than a 404 wearing a link.
Where you stand
| What | How many of 26 |
|---|---|
| Privacy policy linked in the footer, page confirmed live | 6 |
| Terms of use linked in the footer, page confirmed live | 2 |
| Contact reachable from the footer | 13 |
| Medical or professional disclaimer anywhere | 1 |
| Cookie notice or preferences | 0 |
| Affiliate or advertiser disclosure | 0 |
| Billing and cancellation terms | 1 |
| Accessibility statement | 1 |
The good news first, because there genuinely is some, and then the one thing I would fix today.
Tier 1: complete, nothing needed
exercisebuddyfinder.com is your best-covered site by a wide margin. Its footer carries Privacy, Terms, Safety and Trust, Provider Standards, Payment options, Accessibility, Contact and Support, FAQ, About, and Stories, and every one of those pages loads. The footer itself opens with a plain-English disclaimer that buddies are independent, are not employed or supervised by you, and are not doctors, nurses, dietitians, or physical therapists. Auto-renewal, online cancellation, and the 30-day refund window are spelled out on both /pricing and /terms. The privacy policy names what you hold, says you do not collect health information, and explains the provider ID check without retaining the document.
That is a higher standard than most funded startups ship with. I would not change a thing on it.
trainerbooked.com has Privacy, Terms, and Contact linked in the footer, and all three pages load.
Tier 2: the urgent one, and it is not really a footer problem
ajijic.org shows "Privacy Policy" and "Terms of Use" in its footer, both styled as real links, and both point at #. Nothing happens when you click them. There is no page at /privacy and none at /terms; both return your 404. Meanwhile the homepage runs two forms with nine email inputs and Cloudflare Web Analytics.
Then I looked in the repo, and the story got more interesting. Both documents exist and are written: legal/privacy-policy.md and legal/terms-of-service.md, version 0.2, dated May 17. Both carry the same header: draft, needs lawyer review before publishing. The dead links are not an oversight. They are placeholders waiting on a review that has been pending since May.
You already have a plan for it, PLAN-attorney-review-packet.md, and its own summary says the review gates publishing the legal pages, collecting membership money, and answering the referral-fee disclosure question that gates agent outreach. It also flags that the July 10 real-estate referral decision revoked the no-fee assumption the drafts were built on, so the terms need rewriting before counsel sees them anyway.
So the real finding on ajijic.org is not "add a footer link". It is that a stalled legal review is quietly holding up the site's revenue, and in the meantime the site is collecting email addresses behind two links that promise policies and deliver nothing. Those two things want separate answers: finish the review when you are ready, and in the meantime either publish the drafts with a plain "these are current as of" note, or take the links down until they lead somewhere. Leaving them pointing at # is the one option I would rule out.
Tier 3: has a real policy page, just not wired up
bonevoyagedogrescue.com already has a complete privacy policy at /privacy-policy. It loads, it is titled correctly, and no link in the footer points at it. This is a one-line fix, not a writing job.
Tier 4: partial coverage
| Site | Has | Missing |
|---|---|---|
| bobmanthy.com | Privacy, Contact | Terms, and a counseling disclaimer with crisis resources |
| boulderthingstodo.com | Privacy, Contact, Advertise | Terms, advertiser and affiliate disclosure |
| buildamensgroup.com | Privacy | Terms, Contact |
| testosteroneinwomen.com | Privacy | Contact, and a medical disclaimer |
testosteroneinwomen.com is the one I would move up the queue. It is an entire domain about a specific hormone therapy, it collects email, and it carries no disclaimer of any kind. Your own standing rule for health content is a medical-humility frame: your story and your research, not medical advice. That frame belongs on the site, not only in the articles.
Tier 5: no policy links at all
Eighteen sites, sorted by how much I would hurry.
Collecting email right now, so a privacy policy is not really optional:
| Site | What it collects |
|---|---|
| smartstrongalive.com | Email signup, health audience |
| proteinfirstrecipes.com | Two forms, two email fields |
| outdoorboulder.com | Form with email capture |
| recipememoir.com | Form with email capture |
| sponsorlab.ai | Two forms, two email fields, Cloudflare Analytics |
| medspasboulder.com | Contact form with email, B2B medical spas |
| nottoooldforai.com | Form with email capture |
| socialmapped.com | Email signup, paid product |
Content or brochure sites, lower risk but still worth the standard footer:
annettethompson.com, curecaninedisease.com, househelperhub.com, newtoboulder.com, seobeliever.com, tasteboulder.com, verityagentic.ai, vitalency.com
Structural problem, not just a missing link: menopausepracticegrowth.com and rebuildingseminars.com have no footer element at all. There is nowhere to put the links until one exists. rebuildingseminars.com is Bob's GoHighLevel site, so that one is a conversation with him rather than a code change.
Two things worth correcting in the advice you were given
You almost certainly do not need cookie banners. The advice suggested a Cookie Preferences link as part of the default footer. I checked what each site actually loads. You run Cloudflare Web Analytics on four sites, which is cookieless by design and sets no identifier. There is no Meta pixel, no Google Analytics, and no advertising tag anywhere in your portfolio except rebuildingseminars.com, which is Bob's GoHighLevel install and runs GA4 through Tag Manager. Everything else is Google Fonts, YouTube embeds, and static pages.
That means a consent manager would be solving a problem you do not have, and consent banners measurably cost you signups. My recommendation: describe cookies inside the privacy policy, skip the banner and the Cookie Preferences link, and revisit only if you add advertising, a pixel, or GA4 to one of your own sites.
Two sites named in that advice are not real. vitalafterfifty.com does not resolve at all. And ExerciseBuddyFinder was held up as the site most in need of terms covering independent trainers, assumed risk, and subscription disclosure. It already has every one of those, written well, and it is the only site in your portfolio that does. The advice was reasoning about a portfolio it could not see.
The standard footer I would use
Rather than writing 24 separate documents, one master privacy policy and one master terms document with a per-site block covering that site's own forms, analytics, and email list. Roughly 85 percent identical text, 15 percent that genuinely differs.
| Site group | Footer |
|---|---|
| Content and blog sites | Privacy · Terms · Contact |
| Boulder directories (boulderthingstodo, tasteboulder, newtoboulder, outdoorboulder, medspasboulder) | Privacy · Terms · Contact · Advertise · How we list businesses |
| Health sites (smartstrongalive, testosteroneinwomen, proteinfirstrecipes, recipememoir) | Privacy · Terms · Medical Disclaimer · Contact |
| Animal health (curecaninedisease, bonevoyagedogrescue) | Privacy · Terms · Veterinary Disclaimer · Contact |
| B2B services (verityagentic, vitalency, menopausepracticegrowth, seobeliever, socialmapped) | Privacy · Terms · Contact |
| bobmanthy.com | Privacy · Terms · Practice Disclaimer and Crisis Resources · Contact |
| Paid products (exercisebuddyfinder, trainerbooked) | Already correct, no change |
Two notes on that table. The directories need a "how we list businesses" line more than they need an affiliate disclosure, because your actual model there is advertising and verified listings rather than affiliate links; I found no affiliate links on any site. And where a health page carries a specific recommendation, the disclaimer belongs near the recommendation as well as in the footer, which is the same logic the FTC applies to endorsements.
What I would do next, in order
- ajijic.org, decide between publishing the v0.2 drafts now with a dated note or removing the two dead links until counsel has been through them. Either is better than what is there. This is your call, not mine, because it touches the attorney review.
- bonevoyagedogrescue.com, link the policy page that already exists. Five minutes.
- Write the master privacy policy and master terms, using your real data practices: Amazon SES for email, Cloudflare D1 for form submissions, Cloudflare Web Analytics where present, no data sale, no ad networks.
- Roll it to the eight email-collecting sites in tier 5, plus testosteroneinwomen.com and buildamensgroup.com.
- Write the medical and veterinary disclaimers, then roll them with the footers to the health sites.
- Roll the standard footer to the remaining brochure sites.
- Build a footer for menopausepracticegrowth.com, and raise rebuildingseminars.com with Bob.
Steps 1 and 2 I can do immediately. Step 3 is the one that needs a decision from you: I can draft both master documents from what your sites actually do, but a privacy policy names a business contact address for data requests, and I do not want to publish one you have not seen.
One honest caveat, stated once: I am not a lawyer and this is not legal advice. What I can tell you with confidence is what each site does and does not currently say, which is what the table above reports.
How I checked
Both scripts fetched the live rendered pages, not the repos, so this reflects what a visitor sees right now. Every policy URL in the tables above was requested individually and its title and length recorded, which is how the ajijic.org 404s and the unlinked Bone Voyage page surfaced. The registry gap is worth a separate look: exercisebuddyfinder.com is live and is not in SITES.md, which is generated from the Cloudflare API, so either it lives outside that account or the generator has a hole in it.
Published to Annette's hub. Rebuilt from the source markdown, so edit the source and rerun rather than editing this page.