How Starkworth protects payment information — from what's never collected publicly to the security measures protecting the site itself.
Security starts with what Starkworth deliberately does not do: collect bank account numbers, PayPal emails, or wallet addresses on any public-facing form. Registration only asks for your preferred payment method as a category — full details are added later, after approval, inside an authenticated dashboard that isn't publicly accessible.
Every Account Owner and Annotator — payment security applies equally to both roles.
Financial information is exactly the kind of data that shouldn't sit on a public form. Separating "which method do you prefer" (public, low-risk) from "here are my actual account details" (private, authenticated-only) is a deliberate design choice that meaningfully reduces exposure.
Registration asks for a payment method category. After approval, full details are entered inside your authenticated dashboard. Both Account Owner and Annotator portals use real login systems — not a plain link pretending to be a "secure portal" — with password reset available if needed.
Security measures are continuous and always active, not tied to a specific onboarding step — from your first form submission through every future login.
Security isn't a paid tier or add-on — it's the baseline standard applied to every account regardless of role or agreement terms.
If you ever receive a request for your payment details outside your authenticated dashboard — by email, phone, or otherwise — treat it as suspicious and verify directly through Support before responding.
Illustrative example — not a real customer case study
An Annotator receives an email claiming to be from Starkworth, asking them to "confirm" their bank details by replying directly. Because they know legitimate payment-detail requests only happen inside the authenticated dashboard, they recognize this as suspicious, don't respond, and report it to Support instead.
Only inside your authenticated dashboard, after your application or agreement is approved — never on a public form.
No — legitimate staff will never ask for your password; treat any such request as suspicious.
A strict content-security policy, X-Frame-Options for click-jacking protection, and strict referrer controls, alongside enforced HTTPS with HSTS.
Through a real authentication system with hashed credentials and session management, not a shared or guessable link.
Don't respond, and report it directly to Support so it can be reviewed.
No — see the Privacy Policy for the full data handling commitments.
Review the full agreement, register as an Annotator, or chat with our Support assistant.