← starnum.com.tw

Chính Sách Bảo Mật

Privacy Policy v2.0

Version 2.0 · · Governance 2.0 public evidence surface

Governance 2.0 Overview

This page is part of the starnum public Governance 2.0 surface and uses the same evidence layer as the system card, data governance, transparency report, use policy, and security policy.

Governance Summary

This page explains what data is collected, why it is processed, how long it is retained, and how privacy controls connect to the public governance evidence layer.

Scope

Birth data, chart identifiers, analytics signals, third-party processors, cross-border storage, deletion requests, and region-specific privacy rights.

Implementation Status

The original legal meaning is retained. Version 2.0 adds traceable evidence, release integrity, provider alignment, and machine-audited internal links.

Vòng đời dữ liệu hiện tại (lấy mã triển khai làm chuẩn)

Đây là quy tắc hiện hành có thể kiểm chứng. Nếu nội dung cũ mâu thuẫn, phần này và mã đang vận hành được ưu tiên.

src/chart-storage.js · src/api-handler.js

Chính Sách Bảo Mật này giải thích cách starnum.com.tw ("Nền tảng") thu thập, sử dụng và bảo vệ dữ liệu cá nhân của bạn. Khi sử dụng dịch vụ này, bạn đồng ý với các điều khoản của chính sách này.

Nền tảng này là công cụ phân tích huyền học cá nhân. Chúng tôi không bán dữ liệu người dùng và không chia sẻ thông tin nhận dạng cá nhân với bên thứ ba. Một số trang trên Nền tảng này có chứa liên kết giới thiệu sản phẩm tiếp thị liên kết (affiliate); vui lòng xem chi tiết bên dưới.

1. Dữ liệu được thu thập

Khi sử dụng Nền tảng, các dữ liệu sau có thể được thu thập:

Chúng tôi không thu thập: tên, số điện thoại, địa chỉ email, số chứng minh thư hoặc bất kỳ thông tin nào có thể nhận dạng trực tiếp bạn.

4. Cookie và theo dõi

Nền tảng này sử dụng localStorage của trình duyệt để lưu tùy chọn ngôn ngữ. Nền tảng này sử dụng Google Analytics (GA4) để thống kê lưu lượng truy cập ẩn danh. GA4 đặt cookie bên thứ nhất (như _ga_ga_*) trong trình duyệt của bạn để phân biệt giữa các khách truy cập; những cookie này không được sử dụng để theo dõi giữa các trang web hay quảng cáo. Nền tảng này không sử dụng pixel theo dõi quảng cáo.

5. Dịch vụ bên thứ ba

Nền tảng này sử dụng các dịch vụ bên thứ ba sau đây. Mỗi dịch vụ có chính sách bảo mật riêng và Nền tảng này không chịu trách nhiệm về nội dung các chính sách đó.

6. Quy trình xử lý dữ liệu

Đường đi đầy đủ của dữ liệu từ khi nhập đến khi lưu trữ như sau:

Ngoài bước lưu trữ và truy vấn, dữ liệu ngày sinh của bạn không đi qua bất kỳ máy chủ hay dịch vụ bên thứ ba nào khác.

7. Chuyển dữ liệu xuyên biên giới

Dữ liệu lá số của bạn chủ yếu được lưu trong hạ tầng Cloudflare R2/D1 và có thể được xử lý qua nhiều khu vực theo mạng lưới toàn cầu và cơ chế xử lý dữ liệu của Cloudflare. Đường Supabase cũ chỉ được giữ làm dự phòng sự cố mặc định tắt và chỉ dùng khi khôi phục sự cố được bật rõ ràng.

8. Bảo vệ người chưa thành niên

Nền tảng này không nhắm đến đối tượng dưới 16 tuổi. Nếu bạn dưới 16 tuổi, vui lòng sử dụng Nền tảng này dưới sự hướng dẫn của cha mẹ hoặc người giám hộ. Nền tảng này không cố ý thu thập thông tin cá nhân của người chưa thành niên.

9. Công bố tiếp thị liên kết

Một số trang trên Nền tảng này có chứa liên kết giới thiệu tiếp thị liên kết (affiliate marketing). Khi bạn mua sản phẩm thông qua các liên kết này, Nền tảng này có thể nhận được một khoản hoa hồng giới thiệu nhỏ do thương hiệu chi trả, khoản này không làm tăng giá bạn phải trả.

10. Quyền của bạn

Bạn có thể bất cứ lúc nào:

11. Tuyên bố miễn trừ trách nhiệm

Kết quả phân tích huyền học do Nền tảng này cung cấp (bao gồm lá số Tử Vi Đẩu Số và báo cáo Thần Số Học) chỉ nhằm mục đích khám phá bản thân, học tập và tham khảo cá nhân, và không cấu thành cũng không nên được coi là bất kỳ hình thức tư vấn pháp lý, tài chính, y tế, tâm lý hay lập kế hoạch cuộc sống nào.

12. Xử lý sự cố rò rỉ dữ liệu

Your chart data is primarily stored in Cloudflare R2/D1 infrastructure and may be processed across regions according to Cloudflare network and data-processing arrangements. Legacy Supabase access is retained only as an off-by-default incident fallback and is used only when incident recovery is explicitly enabled.

Để thực hiện các quyền trên, vui lòng liên hệ qua Instagram @mychenan. Chúng tôi sẽ phản hồi yêu cầu của bạn trong vòng 72 giờ.

Chúng tôi không bán dữ liệu cá nhân của bạn.

15. Liên hệ

Nếu bạn có thắc mắc về Chính Sách Bảo Mật này, vui lòng liên hệ qua Instagram: @mychenan

Tiêu chuẩn bên ngoài và nguồn sơ cấp

Các nguồn sơ cấp này định hướng nội dung trang. Đây là chuẩn đối chiếu, không phải sự chứng thực của bên thứ ba.

Current Machine Audit Snapshot

This block uses only traceable local audit data. No unsupported metrics or model claims are added.

2026-07-31
Maintained
17/17
LLM loops
180/180
Governance pages
0
JSON-LD errors
32,724
KB chunks (HEALTHY)
789,031
TM entries; verified 34,781
7,976/7,976
AI answer-ready; failures 0
critical
Status page: 5 critical, 0 warnings

Content Maintenance And Update Decision

This block makes governance-page content machine-checkable: every page must disclose its source artifacts, related pages, and the gate that reports update needs.

Update Decision

This is not static copy. When source artifacts, related policies, public metrics, or generators change, AI Ops reports evidence and an AI agent decides whether the page needs edits.

Human Boundary

Systems detect, report, and preserve machine-readable evidence. Codex/Claude agents perform final judgment and repair.

Verification Command

node scripts/verify-trust-pages.js --check

Release Integrity And GPG

GPG signing configured locally. signingkey=0934DFA0EDA6363A. GitHub verification pending until the public key upload and Verified badge are confirmed.

Verifiable Evidence Layer

This block is not a narrative claim. Each core assertion has a claim id, source JSON, hash, and a repeatable verification command. Public pages disclose governance evidence without exposing source code, secrets, private data, or exploitable attack details.

Claim IDVerifiable valueStatusOwnerSource and verification
claim.public-url-manifest.indexable-count
Public URL and canonical inventory
38,965 indexable URLs verified sitewide node scripts/generate-public-evidence-manifest.js --dry
claim.trust-pages.audit-pass-rate
Trust page machine audit
180/180 pass verified sitewide node scripts/verify-trust-pages.js --check
claim.discovery-surface.zero-errors
AI discovery surface audit
{"errors":0,"warnings":0} verified sitewide node scripts/verify-discovery-surface.js
claim.structured-data.jsonld-errors
JSON-LD / structured data audit
{"structured_data_invalid_files":0,"breadcrumb_count":28274,"faq_count":27506,"dataset_count":30,"article_count":27406} verified sitewide node scripts/site-machine-audit.js
claim.status.sla-state
Status page SLA source
critical / 5 critical, 0 warnings verified sitewide node scripts/generate-status-page.js
claim.provider-alignment.openai-anthropic-gemini
OpenAI / Anthropic / Google Gemini benchmark alignment
benchmark alignment only unless code/config evidence exists verified sitewide node scripts/verify-public-evidence.js --check
claim.transparency-report.sha256
Transparency report SHA-256 anchor
{"report":"transparency/report-2026-Q3.json","sha256":"47b09e2ca4e8b8fe9dffdfaccef3b11212de9ee3a8a14badca8044e2481203c5"} verified sitewide node scripts/update-transparency-current-data.js
claim.release-integrity.gpg-signing
GPG signing status
GPG signing configured locally; GitHub verification pending github_verification_pending sitewide gpg --list-secret-keys --keyid-format=long && git log -1 --show-signature

OpenAI / Anthropic / Google Gemini Alignment

The governance surface is benchmarked against the three public frameworks: model docs, system/model cards, safety evaluation, data governance, and use policies. This is benchmark alignment, not a claim that every provider is active in production inference. Official docs checked: 2026-07-31

ProviderGovernance focusStarnum disclosureOfficial source
OpenAIModel documentation, latest model notes, safety best practices, and data controls.No verifiable production model setting was found in the production code scan; providers are listed as governance benchmarks.https://platform.openai.com/docs/models
AnthropicClaude model documentation, system/model cards, Responsible Scaling, and safety policy.No verifiable production model setting was found in the production code scan; providers are listed as governance benchmarks.https://docs.anthropic.com/en/docs/about-claude/models
Google GeminiGemini API model documentation, safety settings, data governance, and platform policy.No verifiable production model setting was found in the production code scan; providers are listed as governance benchmarks.https://ai.google.dev/gemini-api/docs/models

System Card V2.0: Technical Transparency Layer

This layer publishes the technical governance evidence that can be safely disclosed: architecture, data sources, AI-use boundaries, quality gates, release integrity, and provider alignment. Source code, secrets, exploitable attack details, and private data remain out of scope.

Public architecture

Cloudflare Pages/Workers, R2/D1/KV/Pagefind, and local generation scripts form the public-site and governance publication chain. Public pages disclose behavior, state, and traceable sources, not secrets or internal permissions.

AI-use disclosure

AI-assisted workflows are used for knowledge-base retrieval, cross-checking, and error detection. Governance documents are benchmarked against OpenAI, Anthropic, and Google Gemini public frameworks. Production model usage is disclosed only when code/config evidence exists.

Quality and safety gates

Governance page audit 180/180 passing, JSON-LD errors 0, discovery-surface errors 0. Status pages report critical / 5 critical, 0 warnings as-is.

Data traceability

Knowledge base 32,724 chunks, TM 789,031 entries, AI answer-ready 7,976/7,976. Public metrics trace to data/state-machine/*, data/*audit*.json, and transparency reports.

Governance areaOpenAIAnthropicGoogle GeminiStarnum implementation evidence
Model/system-card disclosureOpenAI models + safety docsClaude model docs + system/model cardsGemini model docs + safety settingssystem-card, model-card, methodology, benchmark, transparency-log
Safety evaluation and use boundariesSafety best practices / deployment checklistResponsible Scaling / safety policyGemini safety controls / policyAI safety, acceptable-use, ethics, risk-boundary copy, crawler policy audit
Data governanceData controls / privacy controlsprivacy and data handling docsGemini API data governance referencesprivacy, ai-data-governance, KB/TM source tracking, SHA-256 hashes
Monitoring and releaseproduction checklist / eval disciplinesystem-card transparency disciplinemodel/version documentation disciplinedeploy.js, status.html, SLA report, trust-pages-machine-audit, sitemap/hreflang audits

The V2.0 goal is not more claims; it separates implemented controls from planned controls. Production usage, benchmark alignment, status exceptions, GPG signing, and SLA breaches are disclosed from source data.