WARN Feed

Privacy & terms

Last reviewed 2026-09-24. Plain language, no legalese. If anything here stops being true of the product, the page is wrong and we fix the page.

Who you are dealing with

WARN Feed is published by APProjects, an individual seller operating through Gumroad (seller name approj). Every payment is taken by Gumroad, Inc. as the merchant of record: your card details go to Gumroad, never to us, and your receipt, invoice and any refund come from Gumroad. We do not publish a personal legal name or postal address on this site; if your purchasing process requires a named counterparty and a signed agreement, this product is not a fit and you should not buy it.

Contact: reply to your Gumroad receipt email (it reaches us through Gumroad), or open an issue at github.com/APVentureEngine/warn-act-notices/issues. Both are read on every daily refresh.

What we collect, and why

Reading the free dataset, the site, the feeds and the GitHub repository collects nothing: no account, no cookies, no sign-in, no third-party analytics script. The only two places you can hand us anything are below.

WhenWhatWhy we need itWhere it lives
Buying WARN Watch (paid or free trial) on Gumroad Your email; the employer terms and state codes you type. That is the whole checkout. No credential of yours, ever — no password, no code to generate, no API key, no webhook URL. The email is Gumroad's receipt address and lets us answer a reply. Terms and states are what we match against each day's notices. Your order id, hashed in your own browser (SHA-256), is how the receipt link finds your alert page, whose own address is a random token. Gumroad's servers (the sale record), and a fulfilment file on the private server that runs the daily refresh. Not in the public repository, not in the dataset, not on any public page.
Buying the historical archive on Gumroad Your email; optionally a GitHub username. Gumroad delivers the ZIP to the email. The GitHub username, if given, is used once to invite you to the private mirror repository. Gumroad's servers; the GitHub invitation.
The “stay in touch” box on the landing page Your email. So we can tell you when a new dataset or paid tier is published. (Data changes — a state added, a column renamed — go out in the daily GitHub release instead, which needs no address.) It is Gumroad's follower form, posted straight to Gumroad, and the list is shared across APProjects datasets; unsubscribe from any message. Gumroad's servers only.

Nothing at checkout is a password — how you reach your alert page

Checkout asks for your employer list and, optionally, states. There is no code to generate, no password to pick, and nothing of yours to keep safe. Until 24 September 2026 the checkout also required an “access code” generated on our finder page; that box is gone, because the receipt link already identifies your order and Gumroad's own library is the recovery route. (Orders placed before that date that carried a code: your old email + code lookup address still exists and still forwards to your page.)

Your alert page itself is a public-but-unguessable static page: its address is a random 128-bit token assigned when your order is fulfilled — it is not derived from your email, your order or your list, so nobody who knows any of those can compute it. The “Open my alert page” link on your Gumroad download page carries your order id; the finder hashes it in your own browser (SHA-256("warnwatch-sale|" + order id), nothing is sent anywhere) and forwards to the page. Lost the receipt? Sign in at app.gumroad.com/library with the email you bought with and the same button is there. The page contains your watched terms and the matching public WARN records — never your email or your order id. Anyone you give the link to can read it; it is not listed anywhere and search engines are told not to index it.

We do not take your webhook URL, and you should not give one to anybody

A Slack, Discord or Teams incoming-webhook URL is a live write credential: anyone holding it can post into that channel. Until 19 September 2026 our checkout had an optional box for one, and matches were posted to it. We removed that box, and we no longer ask any customer for a credential of any kind — not at checkout, not afterwards. Nothing was lost: every watch publishes its own private RSS feed. In Slack it is one command — /feed subscribe <your feed address>. In Microsoft Teams, use the channel's bundled Workflows app → Post to a channel when an RSS feed is published (Microsoft retired the old Teams RSS connector in May 2026); classic desktop Outlook has RSS Feeds → Add a new RSS feed. Matches appear in that channel the day we parse them, with the credential staying entirely on your side where you can revoke it without telling us. If you bought before that date and gave us a webhook URL, reply to your receipt and we delete it from the fulfilment record on the next daily refresh.

How long we keep it, and how to delete it

What the site measures about visitors

Each page loads one 1×1 image from the jsDelivr CDN. jsDelivr publishes an aggregate daily request count for that file, which is how we know roughly how many times the site was opened. There is no cookie, no script, no per-visitor record, and no data reaches us other than that public daily number. Gumroad's own checkout and listing pages run Gumroad's analytics, which are Gumroad's, not ours.

Refunds and what you are buying

If the daily rebuild stops — the continuity guarantee

You would be buying a year of daily rebuilds from an automated publisher on a free static host. Being nervous about that is reasonable, so here is exactly what happens if the rebuild stops, and which part of it a script enforces rather than a promise.

Terms of use for the data

← Back to WARN Feed