Legal

Privacy Policy

What we collect, why we collect it, how long we keep it, and who else touches it.

Last updated .

This policy explains how Asheon LTD ("Stabula", "we") handles personal data when you visit our website or use the Stabula Studio. It covers stabula.app and studio.stabula.app.

Who we are

Stabula is operated by Asheon LTD, No. 31, 2nd and 3rd Floor, Soi Sukhumvit 26, Sukhumvit Road, Klong Tan Sub-district, Klong Toei District, Bangkok 10110, Thailand. For anything in this policy, including a request to see, correct, export or delete your data, write to hello@stabula.app.

What we collect

Account data

When you create an account we store your email address, your name if you give one, and an encrypted hash of your password — never the password itself. We record when you confirmed your email, when you last signed in, and failed sign-in attempts, because repeated failures lock an account (see Security).

Workspace data

Everything you build in the Studio belongs to a workspace: requests, the URLs and headers they carry, scenarios and their steps, groups, schedules, notification destinations, API tokens, and the members you invite. If a request needs credentials — a bearer token, an API key, basic-auth details — they are encrypted at rest and are never returned to the browser once saved.

Run data

When you run a test we store what you asked for (the target, the number of simulated users, the duration, the test type), what happened (response times, error rates, throughput, which targets and checks passed), and the runner's own output for the run. Output is cleaned before it is stored: known secret values are replaced with [REDACTED], and the raw k6 banner and script paths are stripped.

Billing data

Paid plans are billed through Stripe. Stripe holds the card; we never see or store card numbers. We store your Stripe customer and subscription identifiers, your plan, and the VU-minutes your workspace has used this month.

Website data

Our servers keep ordinary web logs — IP address, user agent, the path requested, the time — which we use to run the service, to enforce rate limits, and to investigate abuse.

What we do not collect

  • We do not read the bodies of the responses your tests receive. Reports are built from the metrics the runner produces, not from your API's data.
  • We do not sell personal data, and we do not share it for advertising.
  • We do not run third-party advertising or cross-site tracking on our website.

Why we are allowed to use it

We use account and workspace data to provide the service you asked for (performance of a contract), billing data to charge for it and to meet our accounting obligations (legal obligation), and logs and security records to keep the service safe and available (legitimate interests). Where the law that applies to you requires consent for something, we ask for it.

Who else processes it

We use a small number of processors, each for one job. They act on our instructions and are bound by their own agreements.

  • DigitalOcean — hosting and the managed PostgreSQL database. Region: Singapore.
  • Cloudflare — DNS and traffic in front of the application, and R2 object storage for run artifacts.
  • Stripe — payments and subscription management.
  • Resend — confirmation, invitation, run and usage email, sent over their API.
  • Sentry — error reports from the application, which may include the path of a failing request and the identifier of the account that hit it.

This list is kept current. If we add a processor that handles personal data, we update this page.

Where it lives

The application and its database run in Singapore. Run artifacts are stored in Cloudflare R2. Stripe, Sentry and our email provider process data in their own regions, which may be outside your country; their standard data-protection terms cover those transfers.

How long we keep it

  • Account and workspace data: while the account exists.
  • Run results: kept with the workspace, and deleted when the run, the request it belongs to, or the workspace is deleted. A per-plan retention period for the runner's raw output is planned; until it exists, that output is kept for as long as the run is.
  • Billing records: five years, which is what Thai tax and accounting rules require.
  • Web and security logs: 90 days — long enough to investigate an incident, short enough not to become a liability of its own.

What you can ask for

You can ask us to show you the personal data we hold about you, to correct it, to export it, or to delete it. The Studio does most of this directly: Settings → Account changes your name, email and password, and deletes your account. Deleting an account removes your personal data; a workspace's history stays with the workspace, with the deleted user's name removed from it, so other members do not lose their own work. If you are the only owner of a workspace, delete or hand over the workspace first.

Depending on where you live you may also have the right to object to processing, to restrict it, or to complain to a data-protection authority. Write to us first and we will try to settle it.

Testing other people's systems

A load test sends real traffic. You are responsible for having permission to test the target you point Stabula at, and for the personal data you put into a request — headers, bodies, credentials. Do not use production data where test data will do.

Children

Stabula is a tool for developers and is not directed at children. We do not knowingly collect data from anyone under 16.

Changes

When this policy changes we update the date at the top of the page. If a change is significant we tell account holders by email before it takes effect.

Governing law

This policy is governed by the law of Thailand.