← starnum.com.tw

개인정보 처리방침

Privacy Policy v2.0

Version 2.0 · · Governance 2.0 public evidence surface

Governance 2.0 Overview

This page is part of the starnum public Governance 2.0 surface and uses the same evidence layer as the system card, data governance, transparency report, use policy, and security policy.

Governance Summary

This page explains what data is collected, why it is processed, how long it is retained, and how privacy controls connect to the public governance evidence layer.

Scope

Birth data, chart identifiers, analytics signals, third-party processors, cross-border storage, deletion requests, and region-specific privacy rights.

Implementation Status

The original legal meaning is retained. Version 2.0 adds traceable evidence, release integrity, provider alignment, and machine-audited internal links.

현재 데이터 수명주기(코드 구현 기준)

이 절은 현재 검증 가능한 규칙입니다. 이전 문구와 충돌하면 이 절과 실제 구현을 우선합니다.

src/chart-storage.js · src/api-handler.js

이 개인정보 처리방침은 starnum.com.tw(이하 "플랫폼")가 개인 데이터를 어떻게 수집, 사용, 보호하는지 설명합니다. 본 서비스를 이용함으로써 본 방침의 조건에 동의하는 것으로 간주됩니다.

본 플랫폼은 개인 명리 분석 도구입니다. 사용자 데이터를 판매하거나 개인 식별 정보를 제3자와 공유하지 않습니다. 본 플랫폼의 일부 페이지에는 제휴 마케팅(affiliate) 제품 추천 링크가 포함되어 있으며, 자세한 내용은 아래를 참조하십시오.

1. 수집하는 데이터

플랫폼 사용 시 다음 데이터가 수집될 수 있습니다:

본 플랫폼은 이름, 전화번호, 이메일, 주민등록번호 등 개인을 직접 식별할 수 있는 정보는 수집하지 않습니다.

4. 쿠키 및 추적 기술

본 플랫폼은 언어 설정을 저장하기 위해 브라우저 localStorage를 사용합니다. 본 플랫폼은 Google Analytics (GA4)를 사용하여 익명 트래픽 통계를 수집합니다. GA4는 브라우저에 퍼스트파티 쿠키(_ga, _ga_* 등)를 설정하여 방문자를 구별하며, 이 쿠키는 크로스 사이트 추적이나 광고에 사용되지 않습니다. 본 플랫폼은 광고 추적 픽셀을 사용하지 않습니다.

5. 제3자 서비스

본 플랫폼은 아래의 제3자 서비스를 사용합니다. 각 서비스에는 자체 개인정보 처리방침이 있으며, 본 플랫폼은 해당 방침의 내용에 대해 책임을 지지 않습니다.

6. 데이터 처리 흐름

입력부터 저장까지 귀하의 데이터가 이동하는 전체 경로는 다음과 같습니다:

저장 및 조회 단계를 제외하고, 귀하의 출생 데이터는 다른 서버나 제3자 서비스를 거치지 않습니다.

7. 국경 간 데이터 전송

귀하의 명반 데이터는 주로 Cloudflare R2/D1 인프라에 저장되며 Cloudflare의 글로벌 네트워크 및 데이터 처리 방식에 따라 지역을 넘어 처리될 수 있습니다. 기존 Supabase는 기본적으로 꺼진 장애 대응용 예비 경로로만 유지되며, 명시적으로 사고 복구를 활성화한 경우에만 사용됩니다.

13. 방침 업데이트

본 방침에 중요한 변경 사항이 있을 경우, 이 페이지의 업데이트 날짜를 수정하여 알립니다. 서비스를 계속 이용하면 업데이트된 방침에 동의한 것으로 간주됩니다.

14. 개인정보보호법(PIPA) 준수

본 플랫폼은 대한민국 「개인정보 보호법」에 따라 다음 사항을 고지합니다.

개인정보 처리 위탁

본 플랫폼은 서비스 제공을 위해 다음과 같이 개인정보 처리를 위탁하고 있습니다:

개인정보 보호책임자

본 플랫폼의 개인정보 보호에 관한 문의는 다음으로 연락하여 주시기 바랍니다:

정보주체의 권리

정보주체는 「개인정보 보호법」 제35조 내지 제37조에 따라 다음의 권리를 행사할 수 있습니다:

위 권리 행사는 Instagram @mychenan을 통해 요청하실 수 있으며, 요청 접수 후 10일 이내에 조치 결과를 안내드립니다.

본 플랫폼은 이용자의 개인정보를 판매하지 않습니다.

15. 문의하기

본 개인정보 처리방침에 관한 질문은 Instagram으로 문의해 주세요: @mychenan

외부 표준 및 1차 자료

다음 1차 자료는 이 페이지의 판단 기준입니다. 비교 기준일 뿐 제3자가 이 사이트를 보증한다는 뜻은 아닙니다.

Current Machine Audit Snapshot

This block uses only traceable local audit data. No unsupported metrics or model claims are added.

2026-07-31
Maintained
17/17
LLM loops
180/180
Governance pages
0
JSON-LD errors
32,724
KB chunks (HEALTHY)
789,031
TM entries; verified 34,781
7,976/7,976
AI answer-ready; failures 0
critical
Status page: 5 critical, 0 warnings

Content Maintenance And Update Decision

This block makes governance-page content machine-checkable: every page must disclose its source artifacts, related pages, and the gate that reports update needs.

Update Decision

This is not static copy. When source artifacts, related policies, public metrics, or generators change, AI Ops reports evidence and an AI agent decides whether the page needs edits.

Human Boundary

Systems detect, report, and preserve machine-readable evidence. Codex/Claude agents perform final judgment and repair.

Verification Command

node scripts/verify-trust-pages.js --check

Release Integrity And GPG

GPG signing configured locally. signingkey=0934DFA0EDA6363A. GitHub verification pending until the public key upload and Verified badge are confirmed.

Verifiable Evidence Layer

This block is not a narrative claim. Each core assertion has a claim id, source JSON, hash, and a repeatable verification command. Public pages disclose governance evidence without exposing source code, secrets, private data, or exploitable attack details.

Claim IDVerifiable valueStatusOwnerSource and verification
claim.public-url-manifest.indexable-count
Public URL and canonical inventory
38,965 indexable URLs verified sitewide node scripts/generate-public-evidence-manifest.js --dry
claim.trust-pages.audit-pass-rate
Trust page machine audit
180/180 pass verified sitewide node scripts/verify-trust-pages.js --check
claim.discovery-surface.zero-errors
AI discovery surface audit
{"errors":0,"warnings":0} verified sitewide node scripts/verify-discovery-surface.js
claim.structured-data.jsonld-errors
JSON-LD / structured data audit
{"structured_data_invalid_files":0,"breadcrumb_count":28274,"faq_count":27506,"dataset_count":30,"article_count":27406} verified sitewide node scripts/site-machine-audit.js
claim.status.sla-state
Status page SLA source
critical / 5 critical, 0 warnings verified sitewide node scripts/generate-status-page.js
claim.provider-alignment.openai-anthropic-gemini
OpenAI / Anthropic / Google Gemini benchmark alignment
benchmark alignment only unless code/config evidence exists verified sitewide node scripts/verify-public-evidence.js --check
claim.transparency-report.sha256
Transparency report SHA-256 anchor
{"report":"transparency/report-2026-Q3.json","sha256":"47b09e2ca4e8b8fe9dffdfaccef3b11212de9ee3a8a14badca8044e2481203c5"} verified sitewide node scripts/update-transparency-current-data.js
claim.release-integrity.gpg-signing
GPG signing status
GPG signing configured locally; GitHub verification pending github_verification_pending sitewide gpg --list-secret-keys --keyid-format=long && git log -1 --show-signature

OpenAI / Anthropic / Google Gemini Alignment

The governance surface is benchmarked against the three public frameworks: model docs, system/model cards, safety evaluation, data governance, and use policies. This is benchmark alignment, not a claim that every provider is active in production inference. Official docs checked: 2026-07-31

ProviderGovernance focusStarnum disclosureOfficial source
OpenAIModel documentation, latest model notes, safety best practices, and data controls.No verifiable production model setting was found in the production code scan; providers are listed as governance benchmarks.https://platform.openai.com/docs/models
AnthropicClaude model documentation, system/model cards, Responsible Scaling, and safety policy.No verifiable production model setting was found in the production code scan; providers are listed as governance benchmarks.https://docs.anthropic.com/en/docs/about-claude/models
Google GeminiGemini API model documentation, safety settings, data governance, and platform policy.No verifiable production model setting was found in the production code scan; providers are listed as governance benchmarks.https://ai.google.dev/gemini-api/docs/models

System Card V2.0: Technical Transparency Layer

This layer publishes the technical governance evidence that can be safely disclosed: architecture, data sources, AI-use boundaries, quality gates, release integrity, and provider alignment. Source code, secrets, exploitable attack details, and private data remain out of scope.

Public architecture

Cloudflare Pages/Workers, R2/D1/KV/Pagefind, and local generation scripts form the public-site and governance publication chain. Public pages disclose behavior, state, and traceable sources, not secrets or internal permissions.

AI-use disclosure

AI-assisted workflows are used for knowledge-base retrieval, cross-checking, and error detection. Governance documents are benchmarked against OpenAI, Anthropic, and Google Gemini public frameworks. Production model usage is disclosed only when code/config evidence exists.

Quality and safety gates

Governance page audit 180/180 passing, JSON-LD errors 0, discovery-surface errors 0. Status pages report critical / 5 critical, 0 warnings as-is.

Data traceability

Knowledge base 32,724 chunks, TM 789,031 entries, AI answer-ready 7,976/7,976. Public metrics trace to data/state-machine/*, data/*audit*.json, and transparency reports.

Governance areaOpenAIAnthropicGoogle GeminiStarnum implementation evidence
Model/system-card disclosureOpenAI models + safety docsClaude model docs + system/model cardsGemini model docs + safety settingssystem-card, model-card, methodology, benchmark, transparency-log
Safety evaluation and use boundariesSafety best practices / deployment checklistResponsible Scaling / safety policyGemini safety controls / policyAI safety, acceptable-use, ethics, risk-boundary copy, crawler policy audit
Data governanceData controls / privacy controlsprivacy and data handling docsGemini API data governance referencesprivacy, ai-data-governance, KB/TM source tracking, SHA-256 hashes
Monitoring and releaseproduction checklist / eval disciplinesystem-card transparency disciplinemodel/version documentation disciplinedeploy.js, status.html, SLA report, trust-pages-machine-audit, sitemap/hreflang audits

The V2.0 goal is not more claims; it separates implemented controls from planned controls. Production usage, benchmark alignment, status exceptions, GPG signing, and SLA breaches are disclosed from source data.