Effective date: July 19, 2026. Thunderstorm Watch is designed to provide the complete free ZIP result without requiring an account, email address, or payment.
Anonymous ZIP checks
A free check accepts exactly five ASCII digits. The ZIP is sent from your browser to this site’s Cloudflare Pages Function, which forwards it to Zippopotam for centroid lookup and then queries the National Weather Service for active Severe Thunderstorm Watches at that point.
Thunderstorm Watch does not intentionally write anonymous ZIPs or coordinates to its D1 account database, Umami analytics, Stripe, a mailing list, or a customer profile. Successful API responses may be cached briefly at the Cloudflare edge by request URL to improve reliability and limit upstream traffic. Cloudflare and upstream providers may retain transient network or security logs under their own policies.
A ZIP centroid is approximate and is not an exact address.
Analytics
The public site and app use separate self-hosted Umami website properties. Public analytics may record pageviews and low-cardinality events such as active, inactive, stale, error, or map_unavailable. App analytics is limited to similarly bounded product events.
Thunderstorm Watch does not send ZIPs, latitude/longitude, email addresses or hashes, location labels, alert headlines or affected-area text, Stripe customer/subscription IDs, or authentication tokens to Umami. The app property is separate so public and authenticated activity are not intentionally joined into an individual cross-surface profile.
No behavioral advertising or sale of personal data is planned.
Pro account and authentication data
The account service stores only bounded fields needed for the product: a normalized email address, a keyed email helper hash, legal acknowledgement versions/timestamps, minimized subscription references/status, passwordless-session metadata, and operational delivery status. Saved-location data is limited to up to five unique ZIPs, optional labels, ZIP-centroid coordinates and place/state metadata, validated official NWS county/forecast/fire zone URLs, NWS office, timezone, and monitor state. An exact street address is not required.
Magic-link tokens and session cookies are random. Only token hashes are stored. Magic links expire after 15 minutes and are consumed atomically after an explicit confirmation-button POST. The confirmation page does not load analytics or third-party assets. Sessions use a rolling 30-day lifetime and a host-only Secure, HttpOnly, SameSite=Lax cookie. Normal authenticated app use may renew the server and browser expiry together no more than once per 24 hours.
Authentication request responses do not reveal whether an email is registered. Rate-limit keys use bounded keyed hashes rather than raw IP addresses or email addresses.
Billing and transactional email
Production checkout remains disabled during the legal/support launch gate. If checkout is later enabled, Stripe will collect the account email and billing/payment data required for the $29 annual subscription. Thunderstorm Watch does not receive full card details. Local account creation occurs only after a live signed Stripe webhook verifies successful payment for the configured Thunderstorm Watch price.
Cloudflare Email Sending delivers one-time sign-in, welcome/setup, billing-problem, account-deletion, monitoring-enabled/paused, and watch start/update/end messages from the Thunderstorm Watch sender domain. Email has plain-text and HTML versions and does not contain open-tracking pixels. Marketing consent is a separate default-off field and is not implied by checkout or operational email.
Before sending product email, the service can apply local reserved-domain and null-MX suppression. DNS cache keys and recipient suppressions use keyed hashes rather than raw email addresses or raw recipient domains. A known permanent recipient failure may set the account to email_bounced, which blocks new sign-in and product email while an already authenticated session can still view, manage, export, or delete account data.
Providers
Current providers are:
- Cloudflare — DNS, HTTPS, CDN, Pages hosting, Functions, D1 account data, brief edge caching, Email Sending, and security/network logs.
- Stripe — dedicated product/price, signed webhook delivery, subscription records, and hosted customer billing portal. Production checkout is currently disabled.
- NOAA / National Weather Service / Storm Prediction Center — canonical official alert information and safety sources.
- Iowa Environmental Mesonet (IEM) — broad current SPC watch-box geometry for map orientation only.
- Zippopotam.us — ZIP centroid and place/state lookup.
- Self-hosted Umami — privacy-focused public and app analytics with separate website IDs.
- OpenStreetMap contributors and public tile infrastructure — low-volume progressive-enhancement map tiles and attribution during the initial launch.
Each provider may retain data under its own security, fraud, legal, or operational obligations.
Cookies and browser storage
Thunderstorm Watch does not use advertising cookies. The anonymous public checker does not need browser storage to return a ZIP result. An eligible app account uses one essential rolling 30-day session cookie after passwordless confirmation; normal authenticated app use can refresh it at most once per 24 hours. Umami is configured as lightweight analytics and is not used to collect the sensitive fields listed above. Cloudflare may set essential security or abuse-prevention cookies.
Scheduled monitoring and operational records
The dedicated scheduled monitor targets one canonical national NWS Severe Thunderstorm Watch collection request every two minutes. It uses exact NWS zone intersections first, official geometry only when zones cannot determine coverage, and a bounded NWS point fallback only while coverage remains indeterminate. Per-location state retains only saved zones that actually intersect, not unrelated zones elsewhere in a broad watch. A proven exact-zone or geometry watch match remains a fresh watch even if unrelated coverage is incomplete; incomplete coverage can block clear but cannot erase a known watch. It does not use IEM as canonical monitoring truth. A stale, failed, invalid, or over-age official snapshot never creates a clear/watch transition. Ending a tracked watch requires two consecutive fresh authoritative absences.
The service records bounded monitor-run status/counters, poll freshness, current monitor state, a separate last-notified transition baseline, and delivery status/retry metadata. A queued watch email may temporarily retain the bounded location and official-alert fields required to retry that specific message; the payload is cleared after terminal delivery, suppression, failure, location deletion, or account deletion. Raw NWS responses, raw Stripe payloads, authentication tokens, full email message bodies, and PII-rich application logs are not retained as monitor telemetry.
Retention, export, and deletion
Unconsumed magic links expire after 15 minutes. Sessions have a rolling 30-day lifetime, are renewed only through authenticated app use at a bounded interval, and may be revoked sooner. Scheduled bounded cleanup removes magic links more than one day after expiry/consumption, sessions more than seven days after expiry/revocation, and keyed throttle rows more than one day after expiry. It does not delete active sessions or Stripe idempotency records. Active account, subscription, saved-location, and current monitor-state metadata is retained while needed to provide the account. Bounded monitor-run health records are pruned on a rolling basis; expired hashed DNS cache entries and expiring suppressions are also pruned.
Signed-in users can download a bounded JSON export from the account page. Deleting a location suppresses unsent monitoring deliveries, clears their retry schedule/payload, and removes monitor state. Account deletion does the same for unsent monitoring mail before revoking sessions, removing magic links and saved-location/monitor state, clearing recipient suppression and queued payloads, and scrubbing the local email and Stripe identifiers. If a paid subscription has remaining access, deletion requires explicit acknowledgement before immediate Stripe cancellation is requested. Minimized non-identifying billing, security, and delivery status records may be retained where reasonably needed; Stripe and other processors may retain records under their own legal obligations.
Safety and data accuracy
Thunderstorm Watch is not an official government service and provides supplemental information only. Data can be delayed, stale, incomplete, or unavailable. Rely on Wireless Emergency Alerts, NOAA Weather Radio, local authorities, and weather.gov for life-safety decisions.
Questions or changes
The current project contact surface is the About page. A public support mailbox is not advertised. Material privacy changes will be reflected on this page before production checkout is enabled.