Last reviewed 2026-09-24. Plain language, no legalese. If anything here stops being true of the product, the page is wrong and we fix the page.
WARN Feed is published by APProjects, an individual seller operating through Gumroad (seller name approj). Every payment is taken by Gumroad, Inc. as the merchant of record: your card details go to Gumroad, never to us, and your receipt, invoice and any refund come from Gumroad. We do not publish a personal legal name or postal address on this site; if your purchasing process requires a named counterparty and a signed agreement, this product is not a fit and you should not buy it.
Contact: reply to your Gumroad receipt email (it reaches us through Gumroad), or open an issue at github.com/APVentureEngine/warn-act-notices/issues. Both are read on every daily refresh.
Reading the free dataset, the site, the feeds and the GitHub repository collects nothing: no account, no cookies, no sign-in, no third-party analytics script. The only two places you can hand us anything are below.
| When | What | Why we need it | Where it lives |
|---|---|---|---|
| Buying WARN Watch (paid or free trial) on Gumroad | Your email; the employer terms and state codes you type. That is the whole checkout. No credential of yours, ever — no password, no code to generate, no API key, no webhook URL. | The email is Gumroad's receipt address and lets us answer a reply. Terms and states are what we match against each day's notices. Your order id, hashed in your own browser (SHA-256), is how the receipt link finds your alert page, whose own address is a random token. | Gumroad's servers (the sale record), and a fulfilment file on the private server that runs the daily refresh. Not in the public repository, not in the dataset, not on any public page. |
| Buying the historical archive on Gumroad | Your email; optionally a GitHub username. | Gumroad delivers the ZIP to the email. The GitHub username, if given, is used once to invite you to the private mirror repository. | Gumroad's servers; the GitHub invitation. |
| The “stay in touch” box on the landing page | Your email. | So we can tell you when a new dataset or paid tier is published. (Data changes — a state added, a column renamed — go out in the daily GitHub release instead, which needs no address.) It is Gumroad's follower form, posted straight to Gumroad, and the list is shared across APProjects datasets; unsubscribe from any message. | Gumroad's servers only. |
Checkout asks for your employer list and, optionally, states. There is no code to generate, no password to pick, and nothing of yours to keep safe. Until 24 September 2026 the checkout also required an “access code” generated on our finder page; that box is gone, because the receipt link already identifies your order and Gumroad's own library is the recovery route. (Orders placed before that date that carried a code: your old email + code lookup address still exists and still forwards to your page.)
Your alert page itself is a public-but-unguessable static page: its address is a random 128-bit token assigned
when your order is fulfilled — it is not derived from your email, your order or your list, so nobody who knows
any of those can compute it. The “Open my alert page” link on your Gumroad download page carries your
order id; the finder hashes it in your own browser
(SHA-256("warnwatch-sale|" + order id), nothing is sent anywhere) and forwards to the page. Lost the
receipt? Sign in at app.gumroad.com/library with the email
you bought with and the same button is there. The page contains your watched terms and the
matching public WARN records — never your email or your order id. Anyone you give the link to can read it; it is not
listed anywhere and search engines are told not to index it.
A Slack, Discord or Teams incoming-webhook URL is a live write credential: anyone holding it can post into
that channel. Until 19 September 2026 our checkout had an optional box for one, and matches were posted to it. We
removed that box, and we no longer ask any customer for a credential of any kind — not at checkout, not
afterwards. Nothing was lost: every watch publishes its own private RSS feed. In Slack it is one command —
/feed subscribe <your feed address>. In Microsoft Teams, use the channel's bundled Workflows
app → Post to a channel when an RSS feed is published (Microsoft retired the old Teams RSS connector in
May 2026); classic desktop Outlook has RSS Feeds → Add a new RSS feed.
Matches appear in that channel the day we parse them, with the credential staying entirely on your side
where you can revoke it without telling us. If you bought before that date and gave us a webhook URL, reply to your
receipt and we delete it from the fulfilment record on the next daily refresh.
Each page loads one 1×1 image from the jsDelivr CDN. jsDelivr publishes an aggregate daily request count for that file, which is how we know roughly how many times the site was opened. There is no cookie, no script, no per-visitor record, and no data reaches us other than that public daily number. Gumroad's own checkout and listing pages run Gumroad's analytics, which are Gumroad's, not ours.
You would be buying a year of daily rebuilds from an automated publisher on a free static host. Being nervous about that is reasonable, so here is exactly what happens if the rebuild stops, and which part of it a script enforces rather than a promise.
lastBuildDate. That is the same stamp our guard reads — there is no dashboard in between.continuity_guard.py runs on
every build; if the published stamp is older than ten days it refunds every unexpired paid watch — on top
of the 14-day window above — without you asking. The
code is public, so read it before you trust it.lastBuildDate more than ten
days old, reply to your Gumroad receipt: we refund on sight, no argument, whatever the 14-day window says.