개인정보 처리방침
Privacy Policy v2.0Version 2.0 · · Governance 2.0 public evidence surface
Governance 2.0 Overview
This page is part of the starnum public Governance 2.0 surface and uses the same evidence layer as the system card, data governance, transparency report, use policy, and security policy.
Governance Summary
This page explains what data is collected, why it is processed, how long it is retained, and how privacy controls connect to the public governance evidence layer.
Scope
Birth data, chart identifiers, analytics signals, third-party processors, cross-border storage, deletion requests, and region-specific privacy rights.
Implementation Status
The original legal meaning is retained. Version 2.0 adds traceable evidence, release integrity, provider alignment, and machine-audited internal links.
현재 데이터 수명주기(코드 구현 기준)
이 절은 현재 검증 가능한 규칙입니다. 이전 문구와 충돌하면 이 절과 실제 구현을 우선합니다.
- 저장 항목에는 생년월일, 성별, 선택 입력한 출생 시각·장소 메타데이터, 명반 구조, 해석 결과, 언어, 요금제 상태, 접근/제거 토큰이 포함됩니다. 출생 정보는 개인정보이며 익명화되었다고 표현하지 않습니다.
- 주 데이터는 Cloudflare R2, 조회 인덱스와 상태는 D1에 저장합니다. KV는 기한이 있는 복구 백업입니다. Supabase는 기본 비활성화된 이전 장애용 예비 경로이며 일상적인 주 경로가 아닙니다.
- 프런트 조회 기간은 무료 6개월, 일반 1년, 고급·특별 요금제는 무기한입니다. 무료/일반 만료 후 R2 명반 내용은 삭제하고 최소 소비자 인덱스와 주문/감사 기록만 보존합니다.
- 사용자가 제거하면 소프트 삭제 상태를 기록하여 공개 조회·목록·덮어쓰기를 즉시 차단합니다. 보호된 기록과 감사 메타데이터는 계속 보관됩니다. 이는 물리적 삭제가 아니라 프런트 접근 제거입니다.
- AI 생성 또는 번역이 실제로 활성화된 경우에만 작업에 필요한 명반 구조나 문장을 설정된 공급자에게 전송할 수 있습니다. 벤치마크 표의 공급자명은 운영 사용을 뜻하지 않습니다.
src/chart-storage.js · src/api-handler.js
이 개인정보 처리방침은 starnum.com.tw(이하 "플랫폼")가 개인 데이터를 어떻게 수집, 사용, 보호하는지 설명합니다. 본 서비스를 이용함으로써 본 방침의 조건에 동의하는 것으로 간주됩니다.
1. 수집하는 데이터
플랫폼 사용 시 다음 데이터가 수집될 수 있습니다:
- 생년월일 및 출생 시간:자미두수 명반 및 생명 수비학 계산에 사용
- 성별:명반 계산에 사용(대한의 순역에 영향)
- 결혼 여부 및 자녀 유무(선택):관련 궁위 해석을 심화하는 데 사용
- 명반 데이터:조회를 위해 저장되며, 개인 식별 정보는 포함되지 않습니다
본 플랫폼은 이름, 전화번호, 이메일, 주민등록번호 등 개인을 직접 식별할 수 있는 정보는 수집하지 않습니다.
4. 쿠키 및 추적 기술
본 플랫폼은 언어 설정을 저장하기 위해 브라우저 localStorage를 사용합니다. 본 플랫폼은 Google Analytics (GA4)를 사용하여 익명 트래픽 통계를 수집합니다. GA4는 브라우저에 퍼스트파티 쿠키(_ga, _ga_* 등)를 설정하여 방문자를 구별하며, 이 쿠키는 크로스 사이트 추적이나 광고에 사용되지 않습니다. 본 플랫폼은 광고 추적 픽셀을 사용하지 않습니다.
5. 제3자 서비스
본 플랫폼은 아래의 제3자 서비스를 사용합니다. 각 서비스에는 자체 개인정보 처리방침이 있으며, 본 플랫폼은 해당 방침의 내용에 대해 책임을 지지 않습니다.
- Google Analytics (GA4):익명 트래픽 분석 서비스, Google 개인정보 처리방침 적용. GA4는 페이지 조회수, 디바이스 유형, 지리적 지역 등의 익명 데이터를 수집하여 웹사이트 콘텐츠와 사용자 경험을 개선하는 데 사용합니다. Google Analytics 차단 브라우저 부가기능을 통해 수집을 거부할 수 있습니다
- Cloudflare Pages:웹사이트 호스팅 및 CDN 가속, Cloudflare 개인정보 처리방침 적용. Cloudflare는 보안 목적으로 방문자 IP 주소와 브라우저 정보를 기록할 수 있습니다
- Cloudflare R2 / D1: 기본 명반 데이터, 조회 인덱스, 운영 메타데이터를 위한 엣지 저장소
- Google Fonts:폰트 로딩 서비스, Google 개인정보 처리방침 적용
- jsDelivr CDN:오픈소스 라이브러리 로딩 가속, jsDelivr 개인정보 처리방침 적용
- AI / 번역 공급자: 코드와 설정으로 검증되는 경우에만 production 사용으로 표시합니다. 공개 거버넌스 페이지는 시스템 카드와 투명성 보고서를 통해 검증된 공급자만 공개하며, 검증되지 않은 공급자를 활성 production 사용으로 쓰지 않습니다
- Pagefind:사이트 내 검색 기능, 완전히 브라우저에서 실행되며 서버로 데이터가 전송되지 않습니다
- iztro: 자미두수 명반 계산 엔진(오픈소스), 브라우저에서 완전히 로컬로 실행되며 외부 서버로 데이터를 전송하지 않습니다
6. 데이터 처리 흐름
입력부터 저장까지 귀하의 데이터가 이동하는 전체 경로는 다음과 같습니다:
- 입력:브라우저에서 출생 데이터를 입력
- 계산:명반 계산은 전적으로 귀하의 브라우저 내에서 완료(JavaScript 측)
- 저장: 계산 완료 후 명반 결과는 HTTPS를 통해 Cloudflare R2에 기록되고, 조회 인덱스는 Cloudflare D1에 기록됩니다
- 분석 및 번역: AI 보조 분석 또는 다국어 번역이 활성화된 경우, 해석에 필요한 명반 구조와 분석 텍스트만 처리합니다. production 공급자는 시스템 카드의 검증 가능한 설정을 기준으로 합니다
- 조회: 명반 ID로 조회할 때 Cloudflare R2/D1에서 데이터를 읽어 브라우저에서 렌더링합니다
- 프런트 조회 기간은 무료 6개월, 일반 1년, 고급·특별 요금제는 무기한입니다. 무료/일반 만료 후 R2 명반 내용은 삭제하고 최소 소비자 인덱스와 주문/감사 기록만 보존합니다. 사용자가 제거하면 소프트 삭제 상태를 기록하여 공개 조회·목록·덮어쓰기를 즉시 차단합니다. 보호된 기록과 감사 메타데이터는 계속 보관됩니다. 이는 물리적 삭제가 아니라 프런트 접근 제거입니다.
7. 국경 간 데이터 전송
귀하의 명반 데이터는 주로 Cloudflare R2/D1 인프라에 저장되며 Cloudflare의 글로벌 네트워크 및 데이터 처리 방식에 따라 지역을 넘어 처리될 수 있습니다. 기존 Supabase는 기본적으로 꺼진 장애 대응용 예비 경로로만 유지되며, 명시적으로 사고 복구를 활성화한 경우에만 사용됩니다.
13. 방침 업데이트
본 방침에 중요한 변경 사항이 있을 경우, 이 페이지의 업데이트 날짜를 수정하여 알립니다. 서비스를 계속 이용하면 업데이트된 방침에 동의한 것으로 간주됩니다.
14. 개인정보보호법(PIPA) 준수
본 플랫폼은 대한민국 「개인정보 보호법」에 따라 다음 사항을 고지합니다.
개인정보 처리 위탁
본 플랫폼은 서비스 제공을 위해 다음과 같이 개인정보 처리를 위탁하고 있습니다:
- Cloudflare R2 / D1: 기본 명반 데이터, 조회 인덱스, 운영 메타데이터를 위한 엣지 저장소
- Anthropic PBC (미국): 명반 백화문 분석 생성 (천문 데이터만 전송, 개인 식별 정보 미포함)
- DeepL SE (유럽연합): 명반 분석 텍스트 다국어 번역
- Google LLC (미국): 명반 분석 텍스트 번역 및 폰트 로딩
개인정보 보호책임자
본 플랫폼의 개인정보 보호에 관한 문의는 다음으로 연락하여 주시기 바랍니다:
- 연락처: Instagram @mychenan
정보주체의 권리
정보주체는 「개인정보 보호법」 제35조 내지 제37조에 따라 다음의 권리를 행사할 수 있습니다:
- 개인정보 열람 요구권: 본인의 개인정보 처리 현황에 대한 열람을 요구할 수 있습니다
- 개인정보 정정·삭제 요구권: 오류 등이 있는 경우 정정 또는 삭제를 요구할 수 있습니다
- 개인정보 처리정지 요구권: 개인정보의 처리 정지를 요구할 수 있습니다
위 권리 행사는 Instagram @mychenan을 통해 요청하실 수 있으며, 요청 접수 후 10일 이내에 조치 결과를 안내드립니다.
본 플랫폼은 이용자의 개인정보를 판매하지 않습니다.
15. 문의하기
본 개인정보 처리방침에 관한 질문은 Instagram으로 문의해 주세요: @mychenan
외부 표준 및 1차 자료
다음 1차 자료는 이 페이지의 판단 기준입니다. 비교 기준일 뿐 제3자가 이 사이트를 보증한다는 뜻은 아닙니다.
Current Machine Audit Snapshot
This block uses only traceable local audit data. No unsupported metrics or model claims are added.
- data/state-machine/i18n-parity.json: 8,036 parent URLs, 7,976 articles.
- data/kb-machine-audit.json: 3,238 source files, 0 missing coverage, 0 orphan chunks.
- data/discovery-surface-audit.json: 0 errors, 0 warnings.
- data/sla-report.json: critical / 5 critical, 0 warnings.
Content Maintenance And Update Decision
This block makes governance-page content machine-checkable: every page must disclose its source artifacts, related pages, and the gate that reports update needs.
Update Decision
This is not static copy. When source artifacts, related policies, public metrics, or generators change, AI Ops reports evidence and an AI agent decides whether the page needs edits.
Human Boundary
Systems detect, report, and preserve machine-readable evidence. Codex/Claude agents perform final judgment and repair.
Verification Command
node scripts/verify-trust-pages.js --check
data/state-machine/trust-pages.jsondata/public-claim-registry.jsondata/sla-report.json- Related governance pages: Data Governance · Security Policy · Acceptable Use Policy · FAQ
- Update flow:
npm run update:trust-pages→npm run test:trust
Release Integrity And GPG
GPG signing configured locally. signingkey=0934DFA0EDA6363A. GitHub verification pending until the public key upload and Verified badge are confirmed.
Verifiable Evidence Layer
This block is not a narrative claim. Each core assertion has a claim id, source JSON, hash, and a repeatable verification command. Public pages disclose governance evidence without exposing source code, secrets, private data, or exploitable attack details.
| Claim ID | Verifiable value | Status | Owner | Source and verification |
|---|---|---|---|---|
| claim.public-url-manifest.indexable-count Public URL and canonical inventory |
38,965 indexable URLs | verified | sitewide | node scripts/generate-public-evidence-manifest.js --dry |
| claim.trust-pages.audit-pass-rate Trust page machine audit |
180/180 pass | verified | sitewide | node scripts/verify-trust-pages.js --check |
| claim.discovery-surface.zero-errors AI discovery surface audit |
{"errors":0,"warnings":0} | verified | sitewide | node scripts/verify-discovery-surface.js |
| claim.structured-data.jsonld-errors JSON-LD / structured data audit |
{"structured_data_invalid_files":0,"breadcrumb_count":28274,"faq_count":27506,"dataset_count":30,"article_count":27406} | verified | sitewide | node scripts/site-machine-audit.js |
| claim.status.sla-state Status page SLA source |
critical / 5 critical, 0 warnings | verified | sitewide | node scripts/generate-status-page.js |
| claim.provider-alignment.openai-anthropic-gemini OpenAI / Anthropic / Google Gemini benchmark alignment |
benchmark alignment only unless code/config evidence exists | verified | sitewide | node scripts/verify-public-evidence.js --check |
| claim.transparency-report.sha256 Transparency report SHA-256 anchor |
{"report":"transparency/report-2026-Q3.json","sha256":"47b09e2ca4e8b8fe9dffdfaccef3b11212de9ee3a8a14badca8044e2481203c5"} | verified | sitewide | node scripts/update-transparency-current-data.js |
| claim.release-integrity.gpg-signing GPG signing status |
GPG signing configured locally; GitHub verification pending | github_verification_pending | sitewide | gpg --list-secret-keys --keyid-format=long && git log -1 --show-signature |
OpenAI / Anthropic / Google Gemini Alignment
The governance surface is benchmarked against the three public frameworks: model docs, system/model cards, safety evaluation, data governance, and use policies. This is benchmark alignment, not a claim that every provider is active in production inference. Official docs checked: 2026-07-31
| Provider | Governance focus | Starnum disclosure | Official source |
|---|---|---|---|
| OpenAI | Model documentation, latest model notes, safety best practices, and data controls. | No verifiable production model setting was found in the production code scan; providers are listed as governance benchmarks. | https://platform.openai.com/docs/models |
| Anthropic | Claude model documentation, system/model cards, Responsible Scaling, and safety policy. | No verifiable production model setting was found in the production code scan; providers are listed as governance benchmarks. | https://docs.anthropic.com/en/docs/about-claude/models |
| Google Gemini | Gemini API model documentation, safety settings, data governance, and platform policy. | No verifiable production model setting was found in the production code scan; providers are listed as governance benchmarks. | https://ai.google.dev/gemini-api/docs/models |
System Card V2.0: Technical Transparency Layer
This layer publishes the technical governance evidence that can be safely disclosed: architecture, data sources, AI-use boundaries, quality gates, release integrity, and provider alignment. Source code, secrets, exploitable attack details, and private data remain out of scope.
Public architecture
Cloudflare Pages/Workers, R2/D1/KV/Pagefind, and local generation scripts form the public-site and governance publication chain. Public pages disclose behavior, state, and traceable sources, not secrets or internal permissions.
AI-use disclosure
AI-assisted workflows are used for knowledge-base retrieval, cross-checking, and error detection. Governance documents are benchmarked against OpenAI, Anthropic, and Google Gemini public frameworks. Production model usage is disclosed only when code/config evidence exists.
Quality and safety gates
Governance page audit 180/180 passing, JSON-LD errors 0, discovery-surface errors 0. Status pages report critical / 5 critical, 0 warnings as-is.
Data traceability
Knowledge base 32,724 chunks, TM 789,031 entries, AI answer-ready 7,976/7,976. Public metrics trace to data/state-machine/*, data/*audit*.json, and transparency reports.
| Governance area | OpenAI | Anthropic | Google Gemini | Starnum implementation evidence |
|---|---|---|---|---|
| Model/system-card disclosure | OpenAI models + safety docs | Claude model docs + system/model cards | Gemini model docs + safety settings | system-card, model-card, methodology, benchmark, transparency-log |
| Safety evaluation and use boundaries | Safety best practices / deployment checklist | Responsible Scaling / safety policy | Gemini safety controls / policy | AI safety, acceptable-use, ethics, risk-boundary copy, crawler policy audit |
| Data governance | Data controls / privacy controls | privacy and data handling docs | Gemini API data governance references | privacy, ai-data-governance, KB/TM source tracking, SHA-256 hashes |
| Monitoring and release | production checklist / eval discipline | system-card transparency discipline | model/version documentation discipline | deploy.js, status.html, SLA report, trust-pages-machine-audit, sitemap/hreflang audits |
- Sources: data/state-machine/model-card.json, public-bench.json, trust-pages.json, security-headers.json.
- Sources: data/trust-pages-machine-audit.json, data/discovery-surface-audit.json, data/ai-answer-readiness-audit.json.
- Sources: data/kb-machine-audit.json, data/tm/quality-audit-report.json, data/sla-report.json.
- Official benchmark docs checked: 2026-07-31; links are listed in the OpenAI / Anthropic / Google Gemini alignment table.
The V2.0 goal is not more claims; it separates implemented controls from planned controls. Production usage, benchmark alignment, status exceptions, GPG signing, and SLA breaches are disclosed from source data.