Public document register · version 1.0

Policy and governance center

This is the single public index for the rules that govern Advocate Not Adversary. It separates what the website actually does from legal questions that depend on the owner’s location, audience, business structure, provider settings, and other facts.

Status: these documents are operational rules and disclosures for this website. They are not a claim of government approval, legal certification, clinical validation, WCAG conformance certification, HIPAA status, or compliance with every law in every jurisdiction.

Effective date: September 5, 2026. Review is required whenever a data field, provider, AI model, product, audience, owner, contact route, retention practice, or law materially changes, and is scheduled at least quarterly.

Use the right document

Privacy notice

Every site data flow, cookie, processor, retention criterion, adult-use rule, and privacy request path.

Disclosure

Consumer health data

A separate notice for chat text that may reveal autism, disability, mental-health, caregiver, or other health-related information.

Notice and consent framework

Data governance

Data inventory, minimization, access, retention, deletion, processor review, records, and change control.

Operational policy

Terms of use

Service boundaries, educational-use limits, third-party services, intellectual property, and availability.

Terms

Acceptable use

Permitted uses, prohibited conduct, safety limits, enforcement, and a fair reporting path.

Usage policy

Accessibility statement

Accessibility target, features, known limitations, testing status, feedback, and remediation.

Statement

Security and incident response

Public security practices, responsible vulnerability reporting, incident roles, and notification analysis.

Security policy

Chris AI safety protocol

What Chris AI may do, deterministic guardrails, crisis routing, limitations, models, and public safety accounting.

Public safety protocol

AI governance charter

Ownership, risk classes, change gates, testing, provider review, kill-switch authority, and incident review.

Governance charter

Autism evidence register

The dated evidence cards available to Chris AI, source types, conflicts, limitations, and maintenance rules.

Evidence register

Content governance charter

Approval roles, claim classes, family privacy, conflicts, correction records, and takedown decisions.

Governance charter

Commercial disclosures

Product links, owner benefit, Etsy checkout, the third-party advertising safety lock, invalid-traffic boundaries, price and refund responsibility, testimonials, and static sponsorship rules.

Commercial policy

Who decides

RoleAuthority for this websiteLimit
Christopher M. Caballero · OwnerFinal business, publication, feature, data-use, and incident decisions.Owner approval does not replace professional review or applicable law.
Andrew · Corrections ManagementFinds and corrects website errors, maintains approved fixes, and supports this site’s controls.No ownership and no authority over another property, account, client, or business.
Chris AINo authority. It generates bounded educational text after server-enforced screening.It cannot approve policy, diagnose, prescribe, give legal advice, monitor a person, or contact emergency help.
Qualified outside reviewerAdvises only within the reviewer’s actual professional scope.Review must be documented before it is described publicly.

How to raise a concern

Use the Corrections Management human ticket and choose Privacy or safety concern for a privacy request, accessibility barrier, unsafe AI response, security concern, commercial correction, or appeal. Use Owner Services for a final owner decision. Do not include medical records, IEP files, passwords, payment data, or identifying information about a child. The forms are asynchronous and are not emergency services.

For immediate physical danger or an attempt in progress, call 911 or the local emergency number. In the United States, call or text 988 or use 988lifeline.org for crisis support.

Legal applicability is a separate decision

The policies adopt a privacy-protective baseline, but publishing a policy does not decide whether a specific statute applies. For example, state consumer-health-data laws, state comprehensive privacy laws, the Children’s Online Privacy Protection Act, the FTC Health Breach Notification Rule, the EU General Data Protection Regulation, state chatbot laws, and disability-access laws each use their own definitions, thresholds, territorial rules, exemptions, and facts. The owner must obtain qualified legal advice before claiming compliance or expanding into a new audience or service.

Document owner: Christopher M. Caballero · Maintenance: Andrew, Corrections Management · Version 1.0 · Effective September 5, 2026