← starnum.com.tw

Privacy Policy

Privacy Policy v2.0

Version 2.0 · · Governance 2.0 public evidence surface

Governance 2.0 Overview

This page is part of the starnum public Governance 2.0 surface and uses the same evidence layer as the system card, data governance, transparency report, use policy, and security policy.

Governance Summary

This page explains what data is collected, why it is processed, how long it is retained, and how privacy controls connect to the public governance evidence layer.

Scope

Birth data, chart identifiers, analytics signals, third-party processors, cross-border storage, deletion requests, and region-specific privacy rights.

Implementation Status

The original legal meaning is retained. Version 2.0 adds traceable evidence, release integrity, provider alignment, and machine-audited internal links.

Current data lifecycle (code is authoritative)

This is the current verifiable rule set. If legacy copy conflicts, this section and production code control.

src/chart-storage.js · src/api-handler.js

This Privacy Policy explains how starnum.com.tw (the "Platform") collects, uses, and protects your personal data. By using this service, you agree to the terms of this policy.

This Platform is a personal astrology analysis tool. We do not sell user data or share personally identifiable information with third parties. Some pages on this Platform contain affiliate product recommendation links; please see below for details.

1. Data Collected

When you use this Platform, the following data may be collected:

We do not collect: names, phone numbers, email addresses, ID numbers, or any information that directly identifies you.

4. Cookies and Tracking

This Platform uses browser localStorage to store language preferences. This Platform uses Google Analytics (GA4) for anonymous traffic statistics. GA4 sets first-party cookies (such as _ga and _ga_*) in your browser to distinguish between visitors; these cookies are not used for cross-site tracking or advertising. This Platform does not embed advertising tracking pixels.

5. Third-Party Services

This Platform uses the following third-party services. Each has its own privacy policy, and this Platform is not responsible for their policy content.

6. Data Processing Flow

The complete path of your data from input to storage is as follows:

Apart from the storage and retrieval steps, your birth data does not pass through any other servers or third-party services.

7. Cross-Border Data Transfer

Your chart data is primarily stored in Cloudflare R2/D1 infrastructure and may be processed across regions according to Cloudflare network and data-processing arrangements. Legacy Supabase access is retained only as an off-by-default incident fallback and is used only when incident recovery is explicitly enabled.

9. Affiliate Marketing Disclosure

Some pages on this Platform contain affiliate marketing recommendation links. When you purchase products through these links, this Platform may receive a small referral commission paid by the brand, which does not increase the price you pay.

10. Your Rights

You may at any time:

11. Disclaimer

The astrological analysis results provided by this Platform (including Zi Wei Dou Shu charts and Life Path number reports) are intended solely for personal self-exploration, learning, and reference purposes, and do not constitute nor should be regarded as any form of legal, financial, medical, psychological, or life-planning advice.

12. Data Breach Response

If a data security incident occurs with a third-party service used by this Platform, such as Cloudflare storage or a disclosed AI provider, this Platform will notify users as soon as possible through a website announcement, detailing the scope of impact and recommended response measures. As this Platform does not collect email addresses or phone numbers, individual notifications cannot be sent to each user.

13. Policy Updates

If significant changes are made to this policy, the update date on this page will be revised. Continued use of the service constitutes acceptance of the updated policy.

14. Region-Specific Privacy Rights

California Residents (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) provide you with additional rights regarding your personal information:

UK and EEA Residents (UK GDPR / EU GDPR)

If you reside in the United Kingdom or European Economic Area, the following additional provisions apply under the UK GDPR and EU GDPR:

Legal Basis for Processing:

Data Subject Rights:

To exercise any of these rights, contact us via Instagram @mychenan. We will respond to your request within 30 days.

Right to Lodge a Complaint: If you believe that the processing of your personal data infringes applicable data protection law, you have the right to lodge a complaint with the supervisory authority in your country of residence.

We do not sell your personal data.

15. Contact Us

If you have any questions about this Privacy Policy, please contact us via Instagram: @mychenan

External standards and primary sources

These primary sources inform this page. They are benchmarks, not third-party endorsements of this site.

Current Machine Audit Snapshot

This block uses only traceable local audit data. No unsupported metrics or model claims are added.

2026-07-31
Maintained
17/17
LLM loops
180/180
Governance pages
0
JSON-LD errors
32,724
KB chunks (HEALTHY)
789,031
TM entries; verified 34,781
7,976/7,976
AI answer-ready; failures 0
critical
Status page: 5 critical, 0 warnings

Content Maintenance And Update Decision

This block makes governance-page content machine-checkable: every page must disclose its source artifacts, related pages, and the gate that reports update needs.

Update Decision

This is not static copy. When source artifacts, related policies, public metrics, or generators change, AI Ops reports evidence and an AI agent decides whether the page needs edits.

Human Boundary

Systems detect, report, and preserve machine-readable evidence. Codex/Claude agents perform final judgment and repair.

Verification Command

node scripts/verify-trust-pages.js --check

Release Integrity And GPG

GPG signing configured locally. signingkey=0934DFA0EDA6363A. GitHub verification pending until the public key upload and Verified badge are confirmed.

Verifiable Evidence Layer

This block is not a narrative claim. Each core assertion has a claim id, source JSON, hash, and a repeatable verification command. Public pages disclose governance evidence without exposing source code, secrets, private data, or exploitable attack details.

Claim IDVerifiable valueStatusOwnerSource and verification
claim.public-url-manifest.indexable-count
Public URL and canonical inventory
38,965 indexable URLs verified sitewide node scripts/generate-public-evidence-manifest.js --dry
claim.trust-pages.audit-pass-rate
Trust page machine audit
180/180 pass verified sitewide node scripts/verify-trust-pages.js --check
claim.discovery-surface.zero-errors
AI discovery surface audit
{"errors":0,"warnings":0} verified sitewide node scripts/verify-discovery-surface.js
claim.structured-data.jsonld-errors
JSON-LD / structured data audit
{"structured_data_invalid_files":0,"breadcrumb_count":28274,"faq_count":27506,"dataset_count":30,"article_count":27406} verified sitewide node scripts/site-machine-audit.js
claim.status.sla-state
Status page SLA source
critical / 5 critical, 0 warnings verified sitewide node scripts/generate-status-page.js
claim.provider-alignment.openai-anthropic-gemini
OpenAI / Anthropic / Google Gemini benchmark alignment
benchmark alignment only unless code/config evidence exists verified sitewide node scripts/verify-public-evidence.js --check
claim.transparency-report.sha256
Transparency report SHA-256 anchor
{"report":"transparency/report-2026-Q3.json","sha256":"47b09e2ca4e8b8fe9dffdfaccef3b11212de9ee3a8a14badca8044e2481203c5"} verified sitewide node scripts/update-transparency-current-data.js
claim.release-integrity.gpg-signing
GPG signing status
GPG signing configured locally; GitHub verification pending github_verification_pending sitewide gpg --list-secret-keys --keyid-format=long && git log -1 --show-signature

OpenAI / Anthropic / Google Gemini Alignment

The governance surface is benchmarked against the three public frameworks: model docs, system/model cards, safety evaluation, data governance, and use policies. This is benchmark alignment, not a claim that every provider is active in production inference. Official docs checked: 2026-07-31

ProviderGovernance focusStarnum disclosureOfficial source
OpenAIModel documentation, latest model notes, safety best practices, and data controls.No verifiable production model setting was found in the production code scan; providers are listed as governance benchmarks.https://platform.openai.com/docs/models
AnthropicClaude model documentation, system/model cards, Responsible Scaling, and safety policy.No verifiable production model setting was found in the production code scan; providers are listed as governance benchmarks.https://docs.anthropic.com/en/docs/about-claude/models
Google GeminiGemini API model documentation, safety settings, data governance, and platform policy.No verifiable production model setting was found in the production code scan; providers are listed as governance benchmarks.https://ai.google.dev/gemini-api/docs/models

System Card V2.0: Technical Transparency Layer

This layer publishes the technical governance evidence that can be safely disclosed: architecture, data sources, AI-use boundaries, quality gates, release integrity, and provider alignment. Source code, secrets, exploitable attack details, and private data remain out of scope.

Public architecture

Cloudflare Pages/Workers, R2/D1/KV/Pagefind, and local generation scripts form the public-site and governance publication chain. Public pages disclose behavior, state, and traceable sources, not secrets or internal permissions.

AI-use disclosure

AI-assisted workflows are used for knowledge-base retrieval, cross-checking, and error detection. Governance documents are benchmarked against OpenAI, Anthropic, and Google Gemini public frameworks. Production model usage is disclosed only when code/config evidence exists.

Quality and safety gates

Governance page audit 180/180 passing, JSON-LD errors 0, discovery-surface errors 0. Status pages report critical / 5 critical, 0 warnings as-is.

Data traceability

Knowledge base 32,724 chunks, TM 789,031 entries, AI answer-ready 7,976/7,976. Public metrics trace to data/state-machine/*, data/*audit*.json, and transparency reports.

Governance areaOpenAIAnthropicGoogle GeminiStarnum implementation evidence
Model/system-card disclosureOpenAI models + safety docsClaude model docs + system/model cardsGemini model docs + safety settingssystem-card, model-card, methodology, benchmark, transparency-log
Safety evaluation and use boundariesSafety best practices / deployment checklistResponsible Scaling / safety policyGemini safety controls / policyAI safety, acceptable-use, ethics, risk-boundary copy, crawler policy audit
Data governanceData controls / privacy controlsprivacy and data handling docsGemini API data governance referencesprivacy, ai-data-governance, KB/TM source tracking, SHA-256 hashes
Monitoring and releaseproduction checklist / eval disciplinesystem-card transparency disciplinemodel/version documentation disciplinedeploy.js, status.html, SLA report, trust-pages-machine-audit, sitemap/hreflang audits

The V2.0 goal is not more claims; it separates implemented controls from planned controls. Production usage, benchmark alignment, status exceptions, GPG signing, and SLA breaches are disclosed from source data.