Privacy notice and notice at collection · version 2.4

Privacy at Advocate Not Adversary

Different features process different information. Helpful public information does not require an account or payment. Optional member sign-in and hosted membership checkout operate only when administrators enable them and setup is complete. The site does not create an advertising profile or persistent AI conversation memory. Do not submit medical records, IEP files, financial data, legal documents, passwords, addresses, or identifying details about a child.

Operator and scope

Christopher M. Caballero owns and operates Advocate Not Adversary and decides the purposes described here. Andrew handles Corrections Management for this website only. This notice covers advocatenotadversary.com and its same-origin public and administrative features. It does not control Etsy, beehiiv, Groq, NVIDIA, TikTok, YouTube, 988, government sites, or another external service.

Notice at collection

Category and sourcePurposeRecipientsRetention criterion
Chat text and same-tab context supplied by an adult, which may reveal autism, disability, mental-health, caregiver, or other health information.Apply deterministic safeguards, select reviewed autism evidence, and answer the requested general educational question.Cloudflare and, for general inference, configured Groq or NVIDIA routes. Failed routes may cause the bounded request to be attempted at additional routes.No app database transcript. Browser memory lasts until refresh/tab closure. Provider retention follows the current provider terms and account settings described below.
Support information supplied by a visitor: name, reply email, category, subject, message, consent, timestamp, and delivery metadata.Deliver, triage, answer, correct the website, handle a request, prevent abuse, and preserve a reference.Cloudflare, the dedicated domain mailbox, Christopher for Owner Services, and authorized Corrections Management for that service.The site database keeps the newest 500 tickets and up to 25 sent replies per ticket; overflow is removed. Human mailbox copies follow the mailbox provider and owner operating practice. A fixed-day mailbox purge is not currently claimed.
Network and security information such as IP address, request headers, traffic/routing data, human-verification signals, cookies, and rate-limit events, produced by the browser and infrastructure.Deliver the site, authenticate authorized managers, prevent abuse, enforce limits, investigate incidents, and protect availability.Cloudflare and the operator where Cloudflare makes administrative records available.According to the specific security/session limit and Cloudflare service configuration. The application does not attach an IP address to a chat transcript or annual safety count.
Administrative records: site, chat and monetization configuration, revision, actor, timestamp, support-ticket state, content draft, security account-state event, and outbound-email tally.Operate, approve, audit, correct, roll back, and secure this website.Cloudflare and authorized site managers according to role.All saved configuration revisions are retained for rollback and shown 25 at a time; current code does not automatically prune them. Other limits include 200 content drafts, 100 account-state security events, and the limits described in the data register.
Aggregate AI safety events generated by fixed server outcomes.Measure crisis referrals, known-minor boundaries, medical/legal boundaries, and blocked provider output without transcript surveillance.Cloudflare storage and authenticated site managers.Calendar-year aggregate counts; current code does not set a time-based purge. No message, name, email, IP, cookie, or visitor identifier is stored with a count.
Newsletter information deliberately entered into this website’s themed signup form. The browser checks the adult and marketing choices locally; it transmits the email address and provider form flags to Beehiiv. Beehiiv may add signup, consent/suppression, delivery, and email-interaction records.Transmit a requested subscription to Beehiiv, deliver and measure site-related email, and honor unsubscribe.Beehiiv and authorized publication managers under the publication settings. This application does not add the address or checkbox values to its own database.Controlled by the publication settings, suppression obligations, and Beehiiv’s terms. This application does not hold the subscriber database and does not claim that a cross-origin submission was accepted.
Purchase and transaction information entered on Etsy after a visitor follows an external product link.Checkout, payment, delivery, support, refund, fraud prevention, tax, and legal records.Etsy, the applicable seller, payment/service providers, and parties Etsy discloses.Under Etsy, seller, payment, tax, and legal requirements. This application does not collect card data or hold the Etsy order database.
AdSense account-verification metadata generated only if Christopher saves the genuine public publisher ID. The root ads.txt file then names Google and that publisher ID; it contains no visitor identifier or submitted information.Prepare Google’s site and seller-ownership verification without serving an advertisement.Public visitors and crawlers, including Google, because ads.txt is intentionally public. Advocate Not Adversary does not load Google advertising code or send visitor, chat, support, newsletter, purchase, child, or health information through this verification file.Until an authorized site manager removes or replaces the public publisher ID. No Google advertising log is created by this site-side verification response.

Optional member accounts and Stripe-hosted purchases

When enabled, passwordless member sign-in uses an email address, a verified member identifier, short-lived single-use link hashes, and hashed session records. Cloudflare stores these records and sends the requested sign-in email. Link tokens expire after 15 minutes; session tokens after seven days. Expired records are removed in bounded cleanup batches when the service is used, not necessarily at the exact expiration time. Established member records and Stripe customer/account mappings do not yet have an automatic calendar-based purge; the owner must operate an identity-verified account-information and deletion-request process. Signing in does not subscribe you to marketing.

For a requested membership checkout, the application sends the member email and member identifier to Stripe to create or reuse a customer in the correct seller account. Stripe receives payment, billing, fraud-prevention, and transaction information on its own hosted pages. This website stores seller/customer identifiers and bounded checkout and webhook bookkeeping, and queries Stripe for subscription status; it does not collect card numbers or bank-account details. It does not send chat transcripts, health questions, or support-ticket text to Stripe. Billing records may need to be retained by the seller and payment provider for accounting, disputes, or applicable obligations. See Stripe's Privacy Policy.

One-time store checkout similarly shares the purchasing member’s email and identifier with the selected seller’s Stripe customer account. The application stores an order reference, member and seller mappings, product/file identifier, original price and currency, payment mode, checkout-session reference, timestamps, and the last verification outcome. It queries Stripe when you verify or download an order, including payment, refund, and dispute status. Order records and catalog revision snapshots have no automatic time-based purge in this release; the owner must handle verified privacy requests and applicable transaction-retention requirements. At most 10,000 order attempts are stored before new purchases pause for maintenance. Product browsing and free library downloads do not create a member or purchase record.

A separate Secure, HttpOnly, SameSite=Lax ana_member cookie lasts up to seven days and can be revoked with Sign out. It does not grant owner or administrator access. Account requests and hosted payment activity are separate from the anonymous AI safety counters. Contact owner@advocatenotadversary.com for account-information requests without sending payment secrets or health records.

The optional sponsor block contains owner-reviewed plain text and an HTTPS link. It loads no sponsor script, tracking pixel, image, video, or advertising cookie. Following the link visits a third-party site under that site's terms.

Chris AI and health-related text

The public chat presents a separate consumer health data privacy notice and separate unchecked consent before a general model request. The interface transmits the current consent-version marker with each request. The application does not create a named consent profile or save a transcript. Fixed crisis, known-minor, medical, legal, operational, and unavailable responses may be generated locally without sending the message to a model provider.

For allowed general inference, the Worker tries configured model routes one at a time and may retry the same bounded conversation at additional routes if an earlier attempt fails or times out. Groq’s current documentation states that ordinary inference customer data is not retained by default but may be logged for reliability or abuse investigation for up to 30 days unless Zero Data Retention is enabled. This site does not publish proof that account-level Zero Data Retention is enabled. NVIDIA’s public privacy terms apply to its hosted endpoints; the operator has not verified an endpoint-specific zero-retention promise and does not make one.

Support forms

Owner Services and Corrections Management are separate asynchronous human channels. The form sends only its fixed, bounded fields. Cloudflare Turnstile processes browser and network signals and states that it does not access form entries. The site emails the accepted ticket to a fixed domain address and keeps a bounded plain-text administrative copy. Attachment contents are not stored in that database. Do not use a support form for emergencies or submit sensitive records.

Cookies and similar technology

The chat may set a short-lived signed chris_chat cookie after a successful human check. Administrative login uses a signed ana_admin session cookie with a three-hour maximum. Both are Secure, HttpOnly, and SameSite cookies used for security and continuity, not advertising.

The current software does not load Google AdSense code, display third-party advertising, or permit the AdSense control to become Enabled. Saving the genuine public publisher ID may publish it in ads.txt for ownership verification; that response does not set an advertising cookie or send visitor-submitted information. Any future advertising design would require a new code, privacy, consent, accessibility, and owner review before release.

Providers and external destinations

Sale, targeted advertising, and automated decisions

The operator does not sell personal information or consumer health data and does not use site data to make a decision that produces legal or similarly significant effects. The site does not build a sensitive advertising profile, does not use Chris AI or health-related text for advertising, does not pass support or subscriber fields to AdSense, and currently sends no advertising request. Any future advertising proposal would require a fact-specific review of targeted-advertising, sharing, sale, consent, Global Privacy Control, and “Do Not Sell or Share” obligations before code could be released.

Purpose, legal basis, and jurisdiction

Processing is limited to providing a feature the visitor requests, consent where specifically requested, securing and operating the service, handling a support or legal request, and complying with law. If EU or UK data-protection law applies, the precise legal basis may include performance of a requested service, consent—including explicit consent where required for health data—legitimate interests in narrowly securing and administering the service, and legal obligation. Mere worldwide accessibility does not by itself decide territorial applicability.

State privacy laws use thresholds and definitions that depend on facts not established by this page. The site adopts a broad request process without claiming that every statute applies or that every exception is unavailable.

Your choices and requests

You may request confirmation, access, correction, deletion, a description of categories and recipients, consent withdrawal for future processing, unsubscribe, or review of a denied request. Where applicable, you may also appeal and complain to the appropriate regulator. No public account is required. Use Corrections Management, choose Privacy or safety concern, name the feature, approximate date, and the right requested, and provide only the minimum information needed for verification.

The operator will explain records checked, action taken, any inability to locate a transcript that was never stored, provider limits, legally permitted exception, and appeal route. Requests will be handled within the period required by applicable law; no shorter universal response promise is made without confirmed jurisdiction and staffing.

Children

Chris AI and marketing-email signup are limited to adults age 18 or older. The site is not designed to collect personal information directly from children. An unchecked age acknowledgement is not identity verification. Adults must not submit identifying information about a child. If the operator learns that a child’s personal information was collected, the owner will investigate the affected systems and providers, restrict access, pursue deletion where appropriate, and follow applicable notice duties.

Security, transfers, and incidents

The site uses technical and administrative safeguards described in the security and incident-response policy, but no transmission or storage system is guaranteed secure. Cloud services may process information in the United States and other locations described by their terms. If a suspected incident affects personal or health-related data, the owner will investigate and determine applicable individual, regulator, provider, contractual, and law-enforcement notice duties with qualified advice.

Changes

Material changes require an updated effective date, code-to-policy review, and prominent notice or renewed consent where required. A new provider, new data category, targeted advertising, persistent AI memory, precise location, child-directed feature, on-site checkout, or new use of health data may not be added silently.

Document owner: Christopher M. Caballero · Maintenance: Andrew, Corrections Management · Version 2.4 · Effective September 5, 2026