Privacy Policy
1. Who we are
Stubsmith is operated by Bram Hoven, a sole trader established in the Netherlands and trading as Stubsmith, at stubsmith.dev. For GDPR purposes, Stubsmith is the data controller for account and usage data. For API sample data, Stubsmith acts as a data processor on your behalf.
Privacy contact: privacy@stubsmith.dev • General support: support@stubsmith.dev
2. Data we collect
2.1 Account data (controller)
- Email address and name (required for authentication)
- Organization name and member list
- Subscription and billing status (amounts, plan, not full card data)
- Authentication logs (login timestamps, passkey credentials)
2.2 API sample data (processor)
The SDK masks samples at the edge, inside your infrastructure, before anything is transmitted. Stubsmith receives masked bodies plus field and path names. It receives no raw value unless you have approved a keep rule for that specific field; absent such a rule we cannot read the original contents of your sample payloads. You are the data controller for any personal data contained in your samples; our Data Processing Agreement governs this processing.
2.3 Usage and technical data
- Request counts, fingerprint counts, storage usage (for plan enforcement)
- Server access logs (IP address, request path, timestamp), retained 30 days
- Error logs and traces (no sample payload content)
3. How we use your data
- To provide, operate, and improve the Service
- To enforce plan limits and process billing
- To respond to support requests
- To send transactional emails (account, billing, security notifications)
- To comply with legal obligations
We do not sell your data. We do not use your data for advertising.
4. Legal basis (GDPR)
- Contract: processing necessary to provide the Service you signed up for (account data, usage data).
- Legitimate interest: security monitoring, fraud prevention, service improvement.
- Legal obligation: tax records, regulatory compliance.
5. Data sharing
We share data only with:
- UpCloud (Finland), infrastructure hosting (compute and database)
- Scaleway (France), object storage
- Armitage Labs OĆ, trading as Creem (Estonia), payment processing and merchant of record for all subscriptions
- Bunny.net (Slovenia), DNS and CDN for public static surfaces (marketing site, documentation, and dashboard static assets)
- Infomaniak Network SA (Switzerland), email hosting
Every sub-processor is established, and processes data, in the EU/EEA or in Switzerland, a country the European Commission recognises as providing an adequate level of data protection. We rely on no standard contractual clauses, because no personal data is transferred to a country without that recognition.
Creem acts as the merchant of record for all Stubsmith subscriptions: it is the seller of record, collects payment, calculates and remits VAT, and issues your receipt. Card details are entered on Creem's checkout and are never received or stored by Stubsmith.
6. Data retention
- Account data: retained while your account is active. See section 7 for what happens when you delete it.
- Captured request data: masked bodies and metadata are kept in a rolling window per response variant, sized by your plan. Older samples are deleted as newer ones arrive, so the window is bounded by count and nothing expires on a clock. Fingerprints and stubs are kept until you delete them or delete your workspace.
- Billing records: retained 7 years per Dutch tax law. This is a legal obligation and applies even after you delete your account.
- Deletion records: when a workspace is deleted we keep a record that it happened, containing the workspace name, the email address that requested it, and the dates. Nothing else survives.
7. Deleting your account
You can delete your account yourself, from Settings → Account in the dashboard. No email to support is required. What happens depends on your role:
- If you are a member of a workspace someone else owns, your membership and your user record are deleted immediately. The workspace and its data are unaffected.
- If you are the only owner of a workspace, the workspace is deleted along with everything in it: projects, captured request data, fingerprints, stubs, and stored masked bodies. Everyone in the workspace loses access straight away, and any active subscription is cancelled at that moment.
Deleting a workspace is not instant on the storage side. Access ends immediately, but the data is held for 30 days before it is permanently erased, so that a deletion made in error can be reversed by contacting support@stubsmith.dev within that window. After 30 days it is deleted from the database and from object storage and cannot be recovered by us or by you.
Deleting a workspace requires your password and the workspace name typed back, because it cannot be undone once the 30 days have passed.
8. Your rights (GDPR)
EU/EEA residents have the right to: access, rectification, erasure, restriction, portability, and to object to processing. Erasure of your account and its data does not require a request: you can do it yourself at any time (section 7). For anything else, contact privacy@stubsmith.dev. You may also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
9. Security
Account data is protected in transit (TLS 1.2+) and at rest. API samples are masked at the edge before transmission; field and path names are transmitted but raw values are not. See the Security page for architecture details. We conduct regular security reviews and will notify affected users of any breach within 72 hours as required by GDPR.
10. Cookies
The marketing site (stubsmith.dev) sets no tracking or analytics cookies. The application (app.stubsmith.dev) sets a session cookie (ss_session, httpOnly, Secure) and an optional login-hint cookie (ss_logged_in, non-httpOnly, Domain=.stubsmith.dev) used only to show or hide the "Dashboard" button on the marketing site.
11. Changes
We will notify you of material changes to this policy by email and via the dashboard at least 14 days before they take effect.
12. Contact
Privacy questions: privacy@stubsmith.dev
Anything else: support@stubsmith.dev (we reply within 3 business days).