Privacy notice
Every site data flow, cookie, processor, retention criterion, adult-use rule, and privacy request path.
DisclosurePublic document register · version 1.0
This is the single public index for the rules that govern Advocate Not Adversary. It separates what the website actually does from legal questions that depend on the owner’s location, audience, business structure, provider settings, and other facts.
Status: these documents are operational rules and disclosures for this website. They are not a claim of government approval, legal certification, clinical validation, WCAG conformance certification, HIPAA status, or compliance with every law in every jurisdiction.
Effective date: September 5, 2026. Review is required whenever a data field, provider, AI model, product, audience, owner, contact route, retention practice, or law materially changes, and is scheduled at least quarterly.
Every site data flow, cookie, processor, retention criterion, adult-use rule, and privacy request path.
DisclosureA separate notice for chat text that may reveal autism, disability, mental-health, caregiver, or other health-related information.
Notice and consent frameworkData inventory, minimization, access, retention, deletion, processor review, records, and change control.
Operational policyService boundaries, educational-use limits, third-party services, intellectual property, and availability.
TermsPermitted uses, prohibited conduct, safety limits, enforcement, and a fair reporting path.
Usage policyAccessibility target, features, known limitations, testing status, feedback, and remediation.
StatementPublic security practices, responsible vulnerability reporting, incident roles, and notification analysis.
Security policyWhat Chris AI may do, deterministic guardrails, crisis routing, limitations, models, and public safety accounting.
Public safety protocolOwnership, risk classes, change gates, testing, provider review, kill-switch authority, and incident review.
Governance charterThe dated evidence cards available to Chris AI, source types, conflicts, limitations, and maintenance rules.
Evidence registerSourcing, corrections, lived experience, AI-assisted drafting, marketing email, and publication boundaries.
Editorial policyApproval roles, claim classes, family privacy, conflicts, correction records, and takedown decisions.
Governance charterProduct links, owner benefit, Etsy checkout, the third-party advertising safety lock, invalid-traffic boundaries, price and refund responsibility, testimonials, and static sponsorship rules.
Commercial policy| Role | Authority for this website | Limit |
|---|---|---|
| Christopher M. Caballero · Owner | Final business, publication, feature, data-use, and incident decisions. | Owner approval does not replace professional review or applicable law. |
| Andrew · Corrections Management | Finds and corrects website errors, maintains approved fixes, and supports this site’s controls. | No ownership and no authority over another property, account, client, or business. |
| Chris AI | No authority. It generates bounded educational text after server-enforced screening. | It cannot approve policy, diagnose, prescribe, give legal advice, monitor a person, or contact emergency help. |
| Qualified outside reviewer | Advises only within the reviewer’s actual professional scope. | Review must be documented before it is described publicly. |
Use the Corrections Management human ticket and choose Privacy or safety concern for a privacy request, accessibility barrier, unsafe AI response, security concern, commercial correction, or appeal. Use Owner Services for a final owner decision. Do not include medical records, IEP files, passwords, payment data, or identifying information about a child. The forms are asynchronous and are not emergency services.
For immediate physical danger or an attempt in progress, call 911 or the local emergency number. In the United States, call or text 988 or use 988lifeline.org for crisis support.
The policies adopt a privacy-protective baseline, but publishing a policy does not decide whether a specific statute applies. For example, state consumer-health-data laws, state comprehensive privacy laws, the Children’s Online Privacy Protection Act, the FTC Health Breach Notification Rule, the EU General Data Protection Regulation, state chatbot laws, and disability-access laws each use their own definitions, thresholds, territorial rules, exemptions, and facts. The owner must obtain qualified legal advice before claiming compliance or expanding into a new audience or service.
Document owner: Christopher M. Caballero · Maintenance: Andrew, Corrections Management · Version 1.0 · Effective September 5, 2026