FAQ
General
What is Sheaf?
Sheaf is an open-source plural system tracker. It lets you track members, switches (fronting), groups, custom fields, and more. It's a self-hostable replacement for SimplyPlural, with an optional hosted tier at app.sheaf.sh.
Why does Sheaf exist?
SimplyPlural is shutting down, in large part due to the operational and backend burden of running it. Sheaf comes at it from the other direction. It's built by plural systems with years of real-world professional experience running software at scale and building resilient, cost-effective infrastructure for a living, so the parts that tend to quietly break at scale — sync, storage, reliability, database performance, all the behind-the-scenes operational stuff — are the parts we care about the most. We'd rather do those properly than trade feature-completeness for ease of implementation. We're also interested in giving back to the broader plural community through working towards standards for interoperability and, potentially, sync and federation between apps. Sheaf isn't trying to be the only option — it's trying to be the one you can trust to still be around years from now.
At the same time, we believe that software should serve those who use it, and place them in control. Sheaf is designed with an open API and full support for custom clients, full first-party API support with granular access key scopes, data portability, and a focus on usable out-of-the-box defaults but with deep configurability for advanced users. If you want to build your own automated workflows interfacing with Sheaf via the API, or your own custom client, we support and encourage it.
Is Sheaf free?
Yes. Sheaf is free and open-source under the AGPL-3.0 license. You can self-host at no cost other than the underlying compute resources (which need not be expensive - a personal Sheaf instance will happily run on an inexpensive single-board computer at home). The hosted option at app.sheaf.sh is currently free for everyone; a paid tier would in future fund development and infrastructure, not gate core features behind a paywall.
Can I import my SimplyPlural data?
Yes. Export your data from SimplyPlural, then use Sheaf's import feature. You choose exactly what to import - specific members, front history, custom fields, groups.
Do you support imports from any other apps?
Yes. Sheaf currently supports importing system data from PluralKit (file or live via your pk;token), Tupperbox, PluralSpace, Prism (encrypted .prism exports), Ampersand, and any PluralPort file (including ones still written as OpenPlural). Plus, Sheaf's own export imports back as-is, including image bytes, so you can move between Sheaf instances cleanly. Every import shows you a preview of what it's about to do - what comes across, what deduplicates, what exceeds Sheaf's limits and gets shortened - before you commit to it. We plan to keep adding new import formats, starting with the most requested. If you want a particular format supported, mention your interest on our Discord.
Does Sheaf have mobile apps?
Yes.
- Android is on the Google Play Store, or available as a sideloadable APK from GitHub Releases. A Wear OS companion app and complication are included.
- iOS is on the App Store. A watchOS companion app and complication are included.
The API is designed client-first with a full OpenAPI spec, so third-party clients can enjoy the same feature support as official ones.
Is there a Home Assistant integration?
Yes. sheaf-ha is an official integration that brings your system into Home Assistant as entities. It works with the hosted instance and any self-hosted one.
It's early, so expect rough edges and check the issue tracker for what isn't wired up yet. Install it through HACS as a custom repository, then set it up from Settings > Devices & Services.
What you get:
- A binary sensor per member, on while they're fronting, carrying pronouns, colour, fronting-since, and their avatar as the entity picture.
- Sensors for the current fronters (with structured co-fronting data) and the fronter count.
- A Front select for a quick single-member switch, and optional per-member switches so you can build a co-front by toggling several on.
- A
sheaf_front_joinedevent on the HA event bus, so you can trigger automations on a specific member coming to front. - Services to set the front, add or remove a co-fronter, end a front, and set the free-text status.
Updates arrive by polling, by the live front-change stream (push, recommended, and needs no inbound reachability so a LAN-only Home Assistant is fine), or by webhook. All transports keep polling quietly in the background and reconcile against the API, so a missed push doesn't leave you with stale state.
Crucially, you choose which members it can see. By default every member gets an entity, but you can narrow that with the same include/exclude model Sheaf uses for notification visibility. An excluded member gets no entity at all and never appears in the aggregate sensors, the switch options, or any fired event.
Can I wire Sheaf into my own automations?
Yes, and it's a first-class use case rather than an accident. Two ways in, depending on which direction you want the data to flow:
- Sheaf pushes to you. Point a webhook notification channel at any URL you control, with an HMAC signature so you can verify it. Or use ntfy or Pushover if you'd rather not run an endpoint.
- You hold a connection open to Sheaf.
GET /v1/fronts/streamis a Server-Sent Events endpoint that streams your front changes live. It sends a snapshot of who's currently fronting on connect (so you start correct with no race), then the changes as they happen. Because your client dials out, this works from a box with no inbound reachability at all, behind CGNAT included.
The stream authenticates with a scoped API key, so an automation only ever gets the access you granted it, and webhook deliveries are HMAC-signed so your endpoint can tell a real event from a spoofed one. Everything else in the app is under /v1/ with a full OpenAPI spec if you want to build something bigger.
Do the mobile apps work with self-hosted Sheaf instances?
Yes. The app prompts you for your Sheaf server URL before logging in. There is currently one exception - mobile push notifications do not work with selfhosted instances due to technical limitations. We do have a plan to offer them, but it needs coordinated work across the backend and both mobile platforms, so it isn't scheduled yet. In the meantime, self-hosted instances can reach a phone through web push, ntfy, Pushover, or a webhook - see the self-hosting notes for why the published apps can't just be pointed at someone else's push credentials.
Hosted service
Where is the hosted version?
We run two hosted instances:
app.sheaf.sh- the production hosted instance. Free, open signups, real-data-friendly. Governed by the Hosted Service Terms including the §3b production commitments around backups, retention, and best-effort availability.test.sheaf.sh- a public sandbox. Useful for trying things out or chasing bugs without affecting your real data; data on it may be wiped at any time.
Follow the GitHub repo or join Discord for announcements.
Who operates the hosted instances?
Both test.sheaf.sh and app.sheaf.sh are operated by Lupine Systems LLC. Sheaf-the-project is AGPL open source and separate - anyone can self-host or run their own service.
What does the hosted version cost?
It's free at launch. The intent for a future paid tier (if any) is to fund running the service, not to gate core features behind a paywall - any free tier will stay genuinely usable.
Self-hosting
Do I need to be technical to self-host?
You need to be comfortable with a terminal and editing a config file. If you've set up a Minecraft server, or a Discord bot from source, you can handle this. You'll also need a domain.
The all-in-one image handles the fiddly parts for you: it bundles the backend, web UI, and a reverse proxy that fetches and renews a Let's Encrypt certificate on its own, and it generates its own secrets on first start. Set your domain, point DNS at the box, docker compose -f docker-compose.aio.yml up -d. If you're behind CGNAT or can't forward ports, it can also serve over a Cloudflare Tunnel instead. Running the split backend/frontend images with your own reverse proxy is still there for anything bigger.
We plan to release Terraform modules for easy deployment of Sheaf on AWS, and possibly other public clouds. We can not offer support with general selfhosting matters - we would suggest /r/selfhosted and its wiki as starting points.
Can I host Sheaf for other people? Can I charge?
Yes to both. The AGPL allows it. If you modify the code and run it publicly, you must publish your modifications under the same license. If you're charging or providing access to strangers, think about your threat model - you'll be handling sensitive identity data. Seek legal advice if unsure.
Do I have to release modifications to the source for my selfhosted version if I'm not offering it to the public?
No. The AGPL only applies when run for the public. There are no restrictions on personal instances, or those run for a friend group, organisation, or otherwise not open to the public. Note that merely accepting payment for access, while permitted, does not constitute nonpublic if anyone can pay and use the service - in that case the full AGPL terms apply.
Can I use a cloud database?
Yes. Any PostgreSQL 16+ instance - RDS, Cloud SQL, Supabase, Neon, etc. Set DATABASE_URL in your .env. Redis works the same way.
Is it safe to use someone else's hosted Sheaf instance?
It depends on the owner more than anything else. Sheaf's codebase is designed to be resilient and secure-by-default, but open source means anyone can modify it for their own instance. Your trust in a server should only go as far as your trust in the admin - this is true of all system-tracking apps, not just Sheaf.
The most common real-world risk is a hosted instance shutting down because the owner lost interest or couldn't cover costs. You can always export your data and import it on a new server.
Privacy & security
What data does Sheaf collect?
On a self-hosted instance: only what you put in. No telemetry, no analytics, no phoning home.
A hosted service will collect only what's needed to run it (account email, your system data). No selling data, no ads, ever.
Is Sheaf end-to-end encrypted?
No. The server encrypts sensitive fields (email, TOTP secrets, system member data such as names, bios, journals, etc.) at rest, but it accesses the encryption key to these fields at runtime. A server operator could read data if they wanted to - they shouldn't, but technically could. Sheaf has built-in integrity protections to assure as much as possible that the code running on the server has not been modified from the source code, but these mechanisms are not immune to tampering by a highly skilled server operator.
True end-to-end encryption (where the server operators can't read your data at all) is a fundamentally different architecture that also makes features like server-side search impossible. If you want that level of protection, self-host and secure the database with disk-level encryption where you control the key yourself. Doing so is beyond the scope of this FAQ or what we can provide support with, but given a prerequisite of basic self-hosting skills, we would suggest How To Secure A Linux Server as a starting point for learning security hardening; in our opinion, the most important thing in doing so is to take the time to explore and properly define your threat model before you start making architectural decisions.
Why isn't the hosted version end-to-end encrypted?
Beyond the feature-support reasons above: because the people running it are not willing to go to prison rather than comply with legal requests, and the only other option would be to shut down - as happened to Lavabit and other similar services. E2EE means the operator genuinely cannot comply with legal requests for data, which creates serious legal risk far beyond what this project's maintainers are willing to accept.
What about hosting in Switzerland / $random_island_nation / outer space?
No. Jurisdiction is not a defence against legal requests through official channels. Services that use Switzerland as a selling point 'conveniently' neglect to mention that the Swiss government does in fact respond to and assist with legal requests from other countries, and only refuses when they directly target a Swiss citizen. 99.999% of "we host in foo jurisdiction" as marketing copy is security theater. For example, Signal is regarded by all competent cryptographers and privacy experts as the most secure messaging service, despite being hosted predominantly in the United States.
Is my data GDPR-compliant?
Sheaf treats all system data as GDPR Article 9 special category data (data concerning health, or data revealing information about identity). Self-hosted instances are your own responsibility. A hosted service would be operated with full GDPR compliance. Privacy is a fundamental human right, and we aren't interested in your data past the duty of an admin to keep their users safe.
What is "DDoS mode" and why might I see a Cloudflare banner?
By default, the only thing Cloudflare touches for the hosted Sheaf instances is image CDN caching for media served from our S3 origin. Your app traffic does not transit Cloudflare in normal operation.
When we're being actively DDoS'd, we manually flip "DDoS mode" on (an operator script - not automated), at which point Cloudflare proxies all application traffic, with their WAF and Turnstile (CAPTCHA) applied. Cloudflare TLS-terminates at the edge and re-encrypts to our origin, so for the duration of the attack they can see request and response content.
While DDoS mode is on, an in-app banner tells you it's active, and we also announce activation on Mastodon, Bluesky, Tumblr, X, and the project Discord. We turn it off when the attack subsides.
If you'd rather not have your traffic transit Cloudflare under any circumstances, there's a per-account opt-out in your settings. With it on, your session is cleared when DDoS mode is active and you cannot log in until DDoS mode ends - stricter transfer posture at the cost of access during attacks.
Full detail in the Privacy Policy §6 and the Subprocessors list.
What about PluralKit integration?
One-way import is shipped: you can import a PluralKit export file, or pull live from PluralKit using your pk;token. Switch logs are converted to Sheaf front intervals.
Bidirectional sync (pushing switches to PK and/or pulling continuously from PK) is on the roadmap but needs careful design work.
What's PluralPort?
PluralPort is a draft data standard for plural system data, aimed at making exports portable between apps so you aren't locked in. It was called OpenPlural until the standard renamed upstream over a name conflict; the spec version is unchanged, and files written against the old name still import into Sheaf without anything special.
Sheaf is a founding project and ships import and export for v0.1 today - either as a single JSON document or as a .pluralport.zip bundle carrying your images.
Because the spec is still a draft and doesn't model everything yet, we went out of our way to make sure Sheaf isn't a lossy hop. Sheaf data the spec has no field for is preserved under a namespaced extensions key, so a Sheaf → PluralPort → Sheaf round-trip is complete; and data from other apps that Sheaf itself can't model is stored and re-emitted on your next PluralPort export instead of being quietly dropped. A file from another app can therefore pass through Sheaf and come out the other side intact.
Contributing
Can I contribute?
Yes! See CONTRIBUTING.md. Code, bug reports, feature suggestions, and docs improvements are all welcome.
What contributions are most useful right now?
Probably the web UI and Android app, though PRs are welcome across the board.
Terminology
What does "system" mean?
In plurality, a system is the collective term for everyone (members, headmates, alters - terminology varies) who shares a body. Sheaf uses "system" as the top-level organisational unit.
What does "fronting" mean?
Fronting is when a member is actively in control of or present in the body. Sheaf tracks front history so you can log who's fronting when.
What's a "sysmed"?
Short for "sysmedicalist" (borrowed from "transmedicalist" given the extreme parallels) - someone who believes plurality is exclusively a medical condition, gatekeeps who "should" count as plural, and often denies the validity of non-disordered or endogenic systems. This gatekeeping is not welcome in Sheaf's community. See the Code of Conduct.