Are privacy policies any more binding than terms of service? I rarely look at either as a consumer, and for most of my projects, i'm reluctant to even include them. My last ToS was "dont do anything you know you shouldnt do". I imagine popular sites/services might be under more scrutiny, but I still struggle with justifying even having policies or terms at all if they arent enforcable. Maybe its just a PR thing. Or plausible deniability for civil lawsuits and stuff.
Before we wrote our new policy, I looked into this myself because I wondered if we could do without. In the US/Canada and some other places, it's not necessary to have a Privacy Policy (in the EU, it is) depending on what your site does. However, if a user is providing you with data, it is required by privacy laws to let the user know what you will do with it, what you are soliciting from them, and other basic things. For example, EU laws require that we alert the user that we use cookies to keep sessions for users, and how they may turn them off. I would love to have left out things that are obvious but we are required to include certain sections.