# The Refund Is The Pretext And The Register Is The Product: Ask Whether They Hold It Rather Than What It Says, Publish The Record And Never The Verdict, And Recognise That Not Holding Usage Data Is Often The Right Answer

**version** v0.33.61
**date** 20 August 2026
**from** Human (project lead)
**to** Strategy, Product, Legal, the sgit.ai site team

**type** Strategy brief

*Seventeenth of 20 August, and a redirection of the sixteenth at the project lead's direction. The earlier brief's legal analysis is not retracted; it was accurate and it was given the wrong job, and this brief records that plainly and reuses it as an input. The defamation position is checked against the statute and commentary and quoted rather than recalled, because publishing companies' answers is the load-bearing move here and the risk sits on it. Limitation: not legal advice, no solicitor has reviewed it, and one recommendation about publishing third parties' words should be reviewed before the first entry goes live rather than after.*

---

## What This Is

The service reframed from a claims operation into a public register, and the three design decisions that decide whether it works: **the memo says the previous brief was correct about the law and operating at the wrong level, and it is right, because that brief made the legal mapping the product when the law is only evidence and a floor, so what is actually being built is a transparency register in which the refund is the pretext that generates the data and the record of who answers is the asset; the principle to publish first is simple enough to be adopted rather than argued with, that a subscription is a discount for committing to regular use rather than rent on something you have the right to ignore, and it can be drafted as five clauses a company could sign tomorrow, which is more useful than a model law because a standard can be adopted by one company this week and a law cannot; the sharpest change available is the question itself, because proving non-use depends on the provider holding the data and is unprovable when they do not, whereas asking whether they hold a record of your usage at all is a question every company can answer, is comparable across companies, concedes nothing, and produces a publishable table on day one, so question one is do you know rather than how much; the publishing rule is where the whole thing is won or lost, since a body trading for profit must show serious financial loss before a defamation claim gets off the ground and substantial truth is a complete defence, so a dated record of what was asked and what was answered is safe while a characterisation is not, and the estate's own discipline points the same way because a dated test somebody can repeat is evidence and an assertion from a participant is marketing, which gives one rule, publish the record and never the verdict, with no adjective anywhere and the reader left to conclude; the trap to avoid is treating we do not hold that as evasion, because data minimisation makes not retaining granular usage logs a defensible and often correct choice, so scoring it as a failure would punish the privacy-respecting answer and the first person to notice would discredit the register, while the genuinely powerful test is the inconsistency between that answer and the same company's own claims about personalisation and engagement analytics; and the register has a reflexivity problem worth designing against from the start, since being published for refusing teaches every legal team to refuse, so the good path has to be cheap, prominent and answerable once by a published policy rather than per request.** It is the seventeenth document of 20 August (cross-ref: the v0.33.61 subscription recovery brief which this redirects, the v0.33.52 outbound maturity model, the v0.33.59 comparison pages brief, the v0.33.61 user section brief, and the March accountant pack debrief). New contributions: **the level correction recorded, the principle drafted as an adoptable standard, the question changed from usage to whether usage is held, the publish-the-record rule with its two converging justifications, the data minimisation trap named, the inconsistency test proposed, the reflexivity problem and its mitigations, and a four-axis maturity model whose last axis needs no cooperation.**

## What The Previous Brief Got Wrong, Which Was The Level

Recorded plainly, because the corpus's value depends on this being said rather than absorbed.

The brief written earlier today mapped the applicable law carefully and reached accurate conclusions. **The error was not accuracy. It was that the law was promoted to being the product.** That brief's shape was: find the trader's compliance failure, build the claim, recover the money. This memo says the level is wrong, and it is right, because that design makes every case a bespoke legal argument and scales the way legal arguments scale, which is badly.

The correction, in one line:

> **The law is not the product. It is evidence, and a floor. The product is the record of who answers, what they hold, and how they behave when asked.**

**And the earlier brief's findings survive as inputs, mostly by strengthening this one.**

| Finding from the earlier brief | Its role now |
|---|---|
| Not using a service is not a legal basis for a refund | **This is the argument for the register rather than against it.** If the law returned the money, no register would be needed |
| The subscription regime does not commence until spring 2027 | So there is no regulatory pressure on companies to answer today, which makes a voluntary register the only mechanism that exists |
| Access requests by a representative must be honoured, with a high threshold for refusal, one month to respond | Unchanged, and now central rather than supporting, because volume is the point |
| A request sent as leverage is the one refusable case | More important, not less, and it shapes the template |
| General consumer refunds sit outside regulated claims management | More comfortable still, because a register is not a claims operation at all |

So one thing is retracted, which is the framing, and nothing in the research is.

## The Principle, Drafted So It Can Be Adopted

The memo asks for the principle first and for a draft of the law that should exist. **Draft it as a standard rather than as legislation**, because a standard can be adopted by one company next week and a law cannot be adopted by anybody. The law-shaped version is still worth writing, later, as the artefact that goes to consumer groups and committees.

The principle, in the project lead's own framing and sharpened. The project lead: **"subscription levels should be a discount, not a rent."**

> **A subscription is a discount for committing to regular use. It is not rent on something you have the right to ignore.**

That sentence does the work of the whole document, and it is the one to put at the top of the site.

Five clauses, each of which a company either meets or does not, and each observable from outside:

| # | Clause | Observable how |
|---|---|---|
| 1 | **We can tell you how much you used it** | Ask, and see |
| 2 | **We tell you without you having to ask** | Do usage summaries arrive? |
| 3 | **Leaving is as easy as joining, by the same route** | Testable in a browser, without their cooperation |
| 4 | **If you stop using it, we tell you before we charge you again** | Observable over one renewal cycle |
| 5 | **We do not charge for a period you could not have used** | Outages, suspensions, lockouts |

**Every clause is checkable by somebody other than the company**, which is the property that makes this a standard rather than a pledge. The corpus already holds the discipline: a dated test somebody else can repeat is evidence, and an assertion is marketing. A code of conduct whose clauses cannot be checked is the second thing.

## The Question Is Not How Much You Used, It Is Whether They Know

The single change that makes this launchable this month rather than next year.

The memo wants to prove non-use. The project lead: **"once I prove that they don't have, they haven't used it, and I haven't used the service."**

**Non-use is usually unprovable, and it is unprovable in the direction that matters.** If the company holds usage records, they can show it. If they do not, nobody can prove it from their side, and proving it from the consumer's side is weak: an absence of app installs, an absence of emails, an absence of login alerts. Absence of evidence, argued case by case.

So make the first question the one **every company can answer**:

> **Do you hold a record of my usage of this service?**

Compare the two:

| | "How much did I use it?" | **"Do you hold a record of my usage?"** |
|---|---|---|
| Can every company answer it | No | **Yes** |
| Is the answer short | No | **Yes** |
| Comparable across companies | No | **Yes, it is a column** |
| Does it require conceding anything | Yes | **No** |
| Produces a publishable table | Eventually | **On day one** |

The second question follows only where the first is yes, and it follows naturally, because a company that has said it holds the record has no basis for withholding it from the person it is about.

**That is the different level the memo asked for.** It also gives the register a first public artefact quickly, and it is one nobody currently has: a table of consumer subscription companies and whether they can tell you what you used.

## Publish The Record, Never The Verdict

Where this is won or lost, and two independent arguments arrive at the same rule.

The memo wants companies on the record and wants that published. The project lead: **"we should have the data to say, company asks is happy to charge a customer, you know, X amount of pounds for a service not provided."**

**The fact is publishable. The characterisation is the exposure.**

**The legal position**, checked. For a body that trades for profit, a statement is not defamatory unless the harm has caused or is likely to cause **serious financial loss**, which commentary describes as a substantial hurdle that pushes companies towards regulatory complaints instead of litigation. Where a claim is brought, **substantial truth is a complete defence**, and minor inaccuracies do not defeat it. Honest opinion is available where the statement is recognisably opinion and **indicates the basis on which it is held**.

So a dated record of what was asked and what was answered is protected by truth. A characterisation is protected only as opinion, and only where its basis is published beside it. **The record is that basis.** But the deterrent in practice is the cost of defending rather than the likelihood of losing, so the design should avoid the invitation rather than rely on winning.

**The corpus position**, reached from reputation rather than law and pointing identically: a dated test somebody else can repeat is evidence, and an assertion from a participant is marketing.

Which gives the rule:

> **Publish the record. Never the verdict. No adjectives anywhere.**

The entry format that follows:

| Field | Note |
|---|---|
| Company | As named on the contract |
| Date asked | |
| Exactly what was asked | Quoting the published template, by version |
| Date replied, or no reply as at a date | Silence is a row, not a blank |
| What was said | **Verbatim, with the requester's details removed** |
| Nothing else | **No score, no label, no adverb** |

**A page that says asked on 3 March, replied on 2 April, said no, is more damaging than any adjective and it is safe.** The reader supplies the judgement, and a reader who supplies it themselves believes it.

## Not Holding Usage Data Is Often The Right Answer

The own goal to design out before the first entry, and it would otherwise be discovered publicly.

Data protection requires that a controller not keep more personal data than it needs. **A company that does not retain granular usage logs is behaving well by that standard**, and a register that scores "we do not hold that" as evasion punishes the privacy-respecting answer. The first person to point this out would be right, and the register would lose its authority in one exchange.

So three answers, treated as three different things:

| Answer | What it is | How the register records it |
|---|---|---|
| **We hold it, here it is** | The best case | Recorded, with the response time |
| **We hold it and will not give it** | A compliance question about a right the person has | Recorded, verbatim, with the reason given |
| **We do not hold it** | **A legitimate design choice** | **Recorded neutrally, with no penalty** |

**And then the interesting part**, which turns the third row from a dead end into the most valuable cell in the table.

A company that holds no usage record **cannot simultaneously be personalising your experience, recommending content based on what you watched, optimising engagement, or reporting engagement metrics to investors.** Those claims require exactly the data the answer denies holding.

> **The test is not that they refused. It is that the answer to a data subject and the claims in the marketing cannot both be true.**

That is a factual inconsistency, it is checkable by anybody, it lands only where it is actually true, and it needs no characterisation at all. **It is the strongest thing in this design and it is entirely fair**, because a company that genuinely holds nothing and claims nothing passes cleanly.

## The Reflexivity Problem, And Making The Good Path Cheap

A register that publishes refusals teaches legal teams to refuse. That is the predictable response and it would make consumers worse off than before, which is a failure mode worth designing against rather than discovering.

Three mitigations, in order of leverage.

**Make answering a one-time cost rather than a per-request one.** The biggest lever by far. A company that publishes a standing policy page saying what usage data it holds and how to get it can answer every future request with one link. **The register should accept a published policy as an answer** and record it as such. That turns the ask from an ongoing burden into a single piece of work, which is the only version a large company will actually do.

**Publish the good path as loudly as the bad one.** The memo already wants this. The project lead: **"we want to create a system where we reward the good companies that do it well."** The design consequence is that answered in full, in nine days, in a machine-readable format has to be as prominent as any refusal, and the estate's own line applies: a site that only names other people's gaps is not read as research.

**Never publish a first refusal.** Ask twice, with a stated interval, before anything is recorded as a refusal. It removes the cheap shot, it is obviously fair, and it means every published refusal is a considered one.

## The Maturity Model, With Four Axes And One That Needs No Cooperation

The memo asks for a maturity model and this corpus already has the shape of one, from 27 July, built on observable dimensions rather than self-assessment. Four axes here, each observable:

| Axis | The question | Observed how |
|---|---|---|
| **Knows** | Can they tell you what you used? | Ask |
| **Tells** | Do they tell you before charging you again? | Watch one renewal cycle |
| **Speed** | How long from asking to a substantive answer? | Measured in days |
| **Exit** | Is leaving as easy as joining, by the same route? | **Testable in a browser without asking them anything** |

**The last axis is the one to build first**, because it requires no cooperation, no request, and no waiting. Somebody can walk the sign-up path and the cancellation path of fifty companies and publish the click counts and the routes, dated, with the method published so anybody can re-run it. That is a complete, publishable artefact produced without contacting a single company, and it is exactly the reproducible-test discipline settled on 16 August.

It also has a useful property for the register's credibility: it is measured rather than reported, so no company can decline to participate in it.

## What Goes In The Register, And What Stays In The Vault

The memo's instruction is right and the rule already exists in this corpus from earlier today, for a different product. The project lead: **"don't publish any personal data, but publish real world examples."**

| Lives in the public register | Lives in the person's own vault |
|---|---|
| The company, the dates, the template used, the reply verbatim with details removed | Their statements, their full responses, their own claim file |
| The exit path measurements | Anything identifying them |
| The parsers and templates | |

**The unit of the register is a company's behaviour, never a person's case.** That is the same rule reached this morning for the assessment tool: store the choices and never the answers, and the reason is identical, since a personal file assembled in one place is worth more to an attacker than it is to anybody else.

**And the crowdsourced asset is not the data. It is the parsers and the templates.** The memo has this exactly right. The project lead: **"all we need is one person to do that, have a cloud session or an LLM session with it, and then we share those information."**

So the reusable unit is a per-provider workspace: the template that asks this provider the question, the known shape of their reply, and the extraction workflow for whatever format they return. One person works out how to parse one provider's export, and everybody after them gets it for nothing. That is the multiplication the memo is reaching for, and the pipeline for it already exists in this estate, since a debrief from March records exactly this workflow running on the founder's own statements with an agent working inside a shared vault.

## The Business Model, And Why Bring Your Own Model Is The Default

The memo settles it. The project lead: **"the business model here is to charge per tokens."** Everything published under an open licence, briefs written for agents so others can contribute, and payment only for using the hosted environment.

**One correction from this corpus's own experience.** On 6 August it was established that being the meter puts you in the request path, and that the price of being in the path is that the privacy claim moves from architectural to operational. Here the content passing through is **bank statements and subject access responses**, which is more sensitive than the case that finding came from.

So the ordering should be inverted from the usual:

| Mode | Position |
|---|---|
| **Bring your own model** | **The default.** The claim stays architectural, and nothing passes through us |
| Hosted, metered per token | The convenience option, priced per extraction, with retention stated structurally rather than promised |

That is a better story than the alternative and it costs nothing, because the people most likely to care are exactly the people who would use the register first.

The metering itself needs no new work, since the consumption ledger designed on 6 August was made generic on unit type from the first version specifically so a second unit could be added without retrofitting.

## What Ships First

1. **The principle**, published, five clauses, each with how it is checked.
2. **The exit-path measurements**, for fifty companies, with the method published. **No company needs to cooperate and it can be done this week.**
3. **The question**, as one published template, with the merit and authority rules from the earlier brief.
4. **The register schema**, with the three answers distinguished and no verdict field anywhere.
5. **Ten companies asked**, by the founder, using the published template, and the table published with whatever it says including the silences.
6. **The parsers**, as contributors add them.

The acceptance test, in the discipline used repeatedly today:

> A stranger can read the site, adopt the principle, run the exit-path measurement on a company nobody has covered, send the question using the published template, and add a row to the register, without asking anybody for permission or explanation.

**Step two is the one to start with**, and it is the argument for the whole project, because it produces a public, dated, reproducible artefact before a single letter has been sent.

## What This Does Not Try To Be

- **Not a claims service.** The refund is the pretext; the register is the product.
- **Not legal advice.** The defamation position is quoted from the statute and commentary and needs review before the first entry.
- **Not a scoreboard of good and bad companies.** It publishes what was asked and what was said, and the reader concludes.
- **Not a penalty for data minimisation.** Not holding usage records is a legitimate choice and is recorded as one.
- **Not dependent on the 2027 regime.** It works without it and gets a larger surface when it arrives.

## Honest Tensions

| Tension | Note |
|---------|------|
| The refund as pretext | It is what gets people to participate and the register is what has value, so the thing customers want is not the thing being built |
| Publishing the record | It is safe and effective and it will feel toothless to somebody who wanted the site to say what everybody is thinking |
| Neutral treatment of not holding data | It is fair and correct and it removes the easiest headline from the majority of cases |
| The inconsistency test | It is the strongest and fairest instrument here and it requires reading marketing material carefully enough to be sure, which is slow |
| Making the good path cheap | It is the only way to avoid teaching everyone to refuse and it lets a company discharge the ask with one policy page and no real change |
| A founder-led register | It moves fast and it is one person deciding who gets asked, which is the criticism that will be made first |

## Open Questions

| Question | Notes |
|----------|-------|
| Who reviews the first published entry? | The publishing rule is sound and untested, and review costs less before than after |
| What is the interval between the two asks? | It defines a refusal, and it should be published rather than chosen per case |
| Who decides which companies are asked? | A founder-led list is a founder's grievances until the selection rule is published |
| Does a published policy page count as an answer? | It is the main lever for making the good path cheap and it lets a company answer without ever knowing anything |
| How is the exit measurement kept current? | It is the fastest artefact and the one that ages quickest, since a flow can change overnight |
| When does this move to a non-profit? | The memo intends it and the transition is easier before there is a register than after |

## Relationship To Previous Briefs

| Date | Document | Relationship |
|---|---|---|
| 20 Aug | `v0.33.61__strategy-brief__not-using-it-is-not-a-refund-right-money-is-in-trader-compliance-failures-and-the-claim-pool-shrinks-after-spring-2027.md` | The brief this redirects; its framing is superseded and its research is reused as evidence |
| 27 Jul | `v0.33.52__arch-brief__sg-send-agentic-outbound-maturity-model-aomm-reach-motive-freedom-silence-could-has-will-liability.md` | A maturity model built on observable dimensions, which is the shape this one takes |
| 16 Aug | `v0.33.59__strategy-brief__sgit-comparison-pages-as-reproducible-tests-privileges-is-the-missing-column.md` | Dated, re-runnable, method before findings, which the exit measurement follows exactly |
| 20 Aug | `v0.33.61__dev-brief__user-section-is-a-conformance-test-store-the-choices-not-the-answers-high-threat-without-efficacy-produces-denial.md` | The rule that a personal file belongs in the person's own store, transferred here |
| 29 Mar | `debrief__claude_and_sg-vault__workflow-to-create-accountant-pack.md` | The per-provider extraction pipeline, already run once on the founder's own statements |
| 6 Aug | `v0.33.56__arch-brief__sg-send-token-gateway-resale-prohibited-in-line-forced-append-and-settle.md` | Being the meter costing the privacy claim, which is why bring your own model is the default here |

---

## Key Claims

| # | Claim |
|---|-------|
| 1 | The earlier brief's legal analysis was accurate and was given the wrong role, which was to be the product |
| 2 | The law is evidence and a floor, and the register of who answers is the asset |
| 3 | That the law does not return the money is the argument for the register rather than against it |
| 4 | The principle is that a subscription is a discount for regular use rather than rent on an unused right |
| 5 | Drafted as five clauses, each checkable by somebody other than the company |
| 6 | Non-use is usually unprovable, so the first question is whether they hold a usage record at all |
| 7 | That question is answerable by every company, comparable, and produces a table on day one |
| 8 | A body trading for profit must show serious financial loss, and substantial truth is a complete defence |
| 9 | So the rule is publish the record and never the verdict, with no adjectives |
| 10 | Not holding usage data is a legitimate choice under data minimisation and must be recorded neutrally |
| 11 | The strongest instrument is the inconsistency between that answer and the same company's personalisation claims |
| 12 | The exit-path measurement needs no company's cooperation and can be published first |

---

## Sources

- The serious harm requirement, under which a statement is not defamatory unless its publication has caused or is likely to cause serious harm to reputation, and under which harm to the reputation of a body that trades for profit is not serious unless it has caused or is likely to cause that body serious financial loss: https://www.legislation.gov.uk/ukpga/2013/26/section/1
- Commentary on the defences, recording that the truth defence requires the imputation conveyed to be substantially true and that minor inaccuracies need not be proven true, that honest opinion requires the statement to be recognisable as opinion and to indicate the basis on which it is held, and that the serious financial loss requirement is a substantial hurdle which in practice pushes companies towards regulatory complaints rather than litigation: https://inforrm.org/2013/05/21/defamation-act-2013-a-boost-for-free-speech-part-1-serious-harm-truth-and-honest-opinion-timothy-pinto/
- The access request position carried forward from the earlier brief of today, including that a request by an authorised representative must be treated as if made by the person, that there is a high threshold for refusal, that the response is due within one month, and that a request made with no intention of exercising the right is the case the regulator names as refusable: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/right-of-access/when-can-we-consider-a-sar-to-be-manifestly-unfounded-or-excessive/

---

This document is released under the Creative Commons Attribution 4.0 International licence (CC BY 4.0).
