Separate health-data notice · version 1.0
Consumer health data privacy
A chat about autism, disability, mental health, behavior, support needs, caregiving, or services can reveal health-related information even when no medical record is uploaded. This separate notice explains that higher-risk data path before an adult chooses to use Chris AI.
Who controls the data
Christopher M. Caballero operates Advocate Not Adversary and decides why this website processes information. Andrew handles Corrections Management for this website only. Cloudflare supplies the site infrastructure. Groq and NVIDIA supply external model endpoints. Their separate roles and current public notices are listed below.
Health-related data this site may process
| Category | Source | Why it is processed |
|---|---|---|
| Words an adult types about autism, disability, mental or physical health, behavior, communication, supports, services, or caregiving. | The adult using Chris AI. | To screen the request, select reviewed autism evidence, and generate the requested educational reply. |
| A bounded portion of prior messages from the same open browser tab. | The same adult and prior AI replies. | To preserve enough immediate context for the next reply and keep crisis or minor boundaries active. |
| Browser/network security signals, including IP address processed by Cloudflare or Turnstile. | The visitor’s connection and browser. | Site delivery, abuse prevention, human verification, and rate limiting. The application does not attach these signals to a stored chat transcript. |
| Aggregate safety-event counts. | Server rule outcome. | To count crisis referrals, minor boundaries, medical and legal boundaries, and blocked provider output by year. Counts contain no message text or visitor identifier and are not treated as a clinical record. |
Exact chat path
- The visible conversation stays in memory in the open browser tab.
- The Cloudflare Worker receives a bounded message history and applies fixed crisis, minor, medical, legal, and feature-state rules.
- If a general AI reply is allowed, the Worker sends the bounded conversation and a server-controlled instruction to external model routes one at a time. Failed routes may cause the bounded request to be attempted at additional routes from Groq or NVIDIA, for no more than the configured fallback cycles.
- The Worker screens completed model text before returning it. The application does not write the transcript to its Durable Object database, and Worker invocation logging is configured off.
Consent and choice
Before the public interface can send a general chat request, it asks for two separate affirmative choices: one for adult eligibility, AI identity, and terms; and another specifically authorizing the bounded health-related text to be processed by Cloudflare and, if needed, one or more Groq or NVIDIA fallback routes to answer the request. The boxes are unchecked by default. Refusing has no penalty beyond not using the optional chat; the rest of the public website remains available.
The consent choice is held in the current page only and the consent-version marker is transmitted with a chat request; the application does not create a named consent profile. You may withdraw for future processing with the chat’s End chat, clear this tab’s transcript, and withdraw consent control, or by refreshing or closing the browser tab and not sending another message. Withdrawal cannot undo processing that already occurred.
Sharing, sale, advertising, and geofencing
- The operator does not sell consumer health data and does not use it for targeted advertising.
- The operator does not use health data to build an advertising profile, decide eligibility, set a price, or make a legal, educational, employment, housing, credit, or insurance decision.
- The site does not collect precise location and does not use a geofence around health-care facilities.
- Cloudflare processes the request to deliver and protect the service. A failed fallback can cause more than one configured model route to receive the bounded request. No model provider is authorized by this site to market to the visitor.
- The site does not expose chat text to a human support mailbox. A visitor separately chooses what to put into a human support ticket.
Retention and deletion limits
- This application: no database transcript; same-tab memory lasts until page refresh, tab closure, or browser disposal. A short-lived signed security cookie may remain for the configured session period.
- Groq: its current “Your Data in GroqCloud” notice says ordinary inference customer data is not retained by default, but inputs and outputs may be logged for system reliability or abuse investigation for up to 30 days unless Zero Data Retention is enabled. This site does not publish proof that the account-level Zero Data Retention setting is enabled.
- NVIDIA: its hosted endpoint processes requests under NVIDIA’s current agreement and privacy terms. The operator has not verified a public, endpoint-specific zero-retention commitment for the configured hosted NIM routes and therefore does not promise one.
- Cloudflare: its systems process network and customer content under Cloudflare’s service terms and privacy/data-processing documents. Worker invocation logging is disabled in this project; Cloudflare may still process limited network/security data to provide and protect its service.
Your rights and request process
You may ask whether the application holds data linked to you; request access, correction, or deletion; withdraw consent for future processing; ask for the categories of processors or recipients; or appeal a denied request. No site account is required. Use Corrections Management, choose Privacy or safety concern, identify the feature and approximate time, and provide only enough information to verify the request. Christopher or an authorized representative makes the first decision; an appeal receives a second owner review.
Because the application deliberately has no transcript database, it may be unable to locate a chat after the request lifecycle. Provider-held data is subject to the provider’s identification and deletion capabilities. The operator will not pretend to delete data it cannot locate or control and will explain any verified limit or legal exception.
Children and third-party data
Chris AI is limited to adults. It is not designed to collect data directly from children. Adults must not submit identifiable information about a child or any other person. If the operator learns that such information was submitted, the owner should disable access where necessary, document the report, investigate which systems or providers received it, and pursue removal and legally required notices.
Health privacy laws and HIPAA
This notice adopts safeguards informed by Washington’s My Health My Data Act, Nevada’s consumer health data law, comprehensive state privacy principles, and the FTC Health Breach Notification Rule. Whether any one law applies is a fact-specific legal question. The site is not presented as a HIPAA-covered health-care service, covered entity, or business associate, and a general privacy notice does not make it HIPAA compliant.
Provider and authority sources
- Washington RCW Chapter 19.373 — My Health My Data Act
- Nevada 2023 Statutes, Chapter 525, SB 370
- FTC — Health Breach Notification Rule basics
- Groq — Your Data in GroqCloud
- NVIDIA Privacy Policy
- Cloudflare Privacy Policy and Cloudflare Data Processing Addendum
Document owner: Christopher M. Caballero · Maintenance: Andrew, Corrections Management · Version 1.0 · Effective September 5, 2026