Hosted Service Privacy Policy
Effective: 2026-09-16.
This policy covers the hosted instances of Sheaf operated by Lupine Systems LLC at app.sheaf.sh (production) and test.sheaf.sh (public test instance). Self-hosted instances are outside its scope.
For privacy relating to the marketing site sheaf.sh itself, see /privacy/.
1. Data controller
Lupine Systems LLC. See /legal/ for full company identification and contact details.
2. What we collect
2.1 Account data
- Email address (encrypted at rest with XChaCha20-Poly1305)
- Password hash (argon2id)
- Optional TOTP secret (encrypted at rest)
- Recovery codes (hashed)
- Account creation date, last login, approximate login location (IP → country). Full login IP addresses are also kept short-term in the security event log (§2.4).
2.2 System data
Anything you enter into Sheaf: members, fronting history, groups, tags, custom fields, avatars, uploaded files, etc. This is treated as GDPR Article 9 special category data (data revealing information about health or identity).
2.3 Operational logs and metrics
- HTTP access logs (IP, timestamp, route, user-agent, status code) — retained for the minimum time operationally practical, and under no circumstances longer than 30 days.
- Application logs, error traces — retained for the minimum time operationally practical, and under no circumstances longer than 30 days.
- Logs and application-level metrics are collected into a self-hosted Grafana stack (Loki for logs, Prometheus for metrics) running in the same EU region as the rest of the infrastructure. No external observability or analytics provider is involved.
- Low-level infrastructure metrics — EC2 CPU/memory/disk/network, database latency, etc. — are visible to AWS CloudWatch as a built-in property of running on AWS. These describe instance behaviour, not user behaviour, and are governed by the AWS subprocessor relationship in §5. We do not export user-identifying data to CloudWatch.
- We do not use any third-party error-tracking, crash-reporting, or APM service (no Sentry, no Bugsnag, no Datadog, no New Relic, etc.). Errors are captured into the self-hosted log and metrics stack only.
- Email delivery logs (bounces, complaints) - handled by our email provider, Amazon SES in
eu-west-1(see /service/subprocessors/). Delivery events reach us as bounce and complaint notifications so we can stop sending to addresses that are rejecting mail. We retain these no longer than 30 days.
2.4 Security event log
To detect credential-stuffing and other account-abuse attacks - one IP failing logins against many accounts, an account being hammered with reset requests, a sign-in from an unexpected place - we keep a short, append-only log of authentication events tied to your account:
- Logins (successful and failed, with the failure reason), registrations, password-reset requests and completions, and password changes.
- For each event: the originating IP address (stored in full, not reduced to country), the timestamp, and the user-agent.
This is distinct from the operational HTTP logs in §2.3: it is account-linked and exists specifically for abuse detection and incident investigation, under the legitimate-interest basis in §3. Failed logins against an address that was never registered are recorded against the IP only - we do not store the attempted email. Administrative actions on your account additionally record the acting administrator's IP.
The security event log is retained for a maximum of 30 days (the default; the window is configurable per instance) and then purged. It is included in your data export and in any access request.
2.5 Payment data (if applicable)
If you subscribe to a paid tier, payment information is handled directly by our payment processor. We receive only: last-four of card, billing country, subscription status. We do not see or store full card numbers.
3. Legal bases for processing (GDPR)
| Purpose | Legal basis |
|---|---|
| Providing the service (account, member and front tracking, etc.) | Art. 6(1)(b) — performance of contract |
| Processing Article 9 data (members, fronts, identity-related fields) | Art. 9(2)(a) — explicit consent |
| Security, abuse prevention, logging | Art. 6(1)(f) — legitimate interest |
| Billing and tax records | Art. 6(1)(c) — legal obligation |
| Email for account notifications | Art. 6(1)(b) — performance of contract |
4. How long we keep it
- Account data: for the life of your account, plus a grace period of 7 days after deletion is requested, during which you can cancel the deletion.
- System data: same as account data. Deleted irrecoverably after the grace period elapses.
- Logs: as noted in §2.3.
- Security event log: maximum 30 days, then purged (see §2.4).
- Billing records: retained for the statutory period required by tax law (typically 7 years in the US).
Once the grace period elapses, your account and all associated data are deleted from the live database. Copies persist in encrypted backups for a minimum of 7 days and a maximum of 30 days, after which they are overwritten in the normal course of rotation. After that point the data is gone from our systems.
Backups are encrypted asymmetrically: the public encryption key lives on the backup-writing infrastructure, while the private decryption key is held offline and is required to read a backup at all. This means an attacker who compromises the live infrastructure cannot read historical backups, and a backup leak in isolation discloses only ciphertext.
5. Subprocessors
We use third parties to run the service. See /service/subprocessors/ for the canonical, up-to-date list.
5.1 User-configured integrations
If you connect Sheaf to a third-party notification destination (such as Pushover, ntfy, a generic webhook, or any future integration of this kind), data flows from the hosted instance to that destination as you direct it. Those third parties are not subprocessors of Lupine Systems — we don't engage them on our own behalf; you do, by configuring the integration — but the data still reaches them, and their own terms and privacy policies govern what they do with it. You are the controller of that flow; we are the conduit.
Disable any such integration in Settings to stop the flow. Removing the integration also clears the credentials we hold for it.
6. International transfers
Primary infrastructure for the hosted Sheaf instances runs in the European Union, on AWS in eu-west-1 (Ireland). EC2 compute, the primary database, object storage, and encrypted backups all stay within the EU. No bulk replication of personal data outside the EU takes place.
Transactional email is sent via Amazon SES in the same eu-west-1 region, so composing, sending, and bounce/complaint handling all happen inside the EU. (Once a message leaves for the recipient's own mail provider, it is subject to wherever that provider operates, which is inherent to email and outside anyone's control but the recipient's.)
One category of routine transfer occurs via subprocessors (see /service/subprocessors/):
- Cloudflare handles image CDN/caching for media served from our S3 origin in normal operation; application traffic does not transit Cloudflare in this mode. We manually enable DDoS mode (via an operator script) in response to an active attack, at which point Cloudflare proxies all application traffic with their WAF and Turnstile (CAPTCHA) applied. During DDoS mode, Cloudflare TLS-terminates at the edge and re-encrypts to our origin, so they can see request and response content for the duration of the incident. Cloudflare operates a global edge network including US nodes. Activation is signposted by an in-app banner and announced on the status channels listed in Terms §3b. Users of the hosted app can avoid routine image-CDN exposure by not uploading images and not hotlinking. For DDoS-mode routing, an account-level opt-out is available in account settings: with it enabled, the user's session is cleared when DDoS mode is active and they cannot log in until DDoS mode ends - a stricter transfer posture at the cost of access during attacks.
Where these transfers involve EU personal data being processed outside the EU, we rely on:
- the EU-US Data Privacy Framework, under which both AWS and Cloudflare are certified, as the primary transfer mechanism; and
- the Standard Contractual Clauses (2021 EU Commission decision) as a fallback.
UK → non-UK transfers rely on the UK Addendum to the SCCs and the UK extension to the Data Privacy Framework on the same basis.
7. Your rights
Under GDPR, UK GDPR, CCPA/CPRA and comparable laws you have the right to:
- Access — request a copy of your personal data (Sheaf provides self-service export)
- Rectification — correct inaccurate data (editable in-app)
- Erasure — delete your account and data (self-service with grace period)
- Portability — receive your data in a structured, machine-readable format (JSON export)
- Restriction / Objection — limit or object to specific processing
- Withdrawal of consent — for Article 9 data, you can withdraw consent; this effectively means account deletion since the service cannot operate without it
- Complain to a supervisory authority — in the EU, your local DPA; in the UK, the ICO
Where your jurisdiction does not grant you these rights as a matter of law, we extend them as a matter of policy: anyone may exercise the rights set out above by contacting us, regardless of where they are. Practical limitations apply only where retention is required by law that does bind us (e.g. billing records under US tax law). The "complain to a supervisory authority" right is the one exception, since it depends on a supervisory authority you can complain to actually existing in your jurisdiction.
To exercise any right that isn't handled in-app, email [email protected].
8. Security
Summary (full detail in the Sheaf repo):
- Application-level encryption of sensitive fields (email, TOTP secrets) with XChaCha20-Poly1305
- TLS 1.2+ for all connections
- Scoped API keys; JWT access tokens with short TTL and rotating refresh tokens
- Optional 2FA (TOTP)
- Database encryption at rest (disk level) on hosted infrastructure
- Backups encrypted asymmetrically; the private decryption key is held offline (see §4)
No system is perfectly secure. See §10 for what happens if something goes wrong.
Responsible disclosure: [email protected], GitHub Security Advisories, or the project's SECURITY.md.
9. Cookies and tracking on the hosted app
The hosted app sets two cookies, both strictly necessary to operate it:
- a session cookie identifying your logged-in session
- a CSRF token protecting forms and state-changing requests from cross-site request forgery
Both are first-party, HttpOnly where applicable, Secure, and SameSite=Lax or stricter. They are cleared when you log out.
We do not use:
- analytics (no Google Analytics, Plausible, Fathom, or anything else)
- advertising or ad-tech cookies
- third-party tracking pixels or fingerprinting
- session-replay tools
- any embedded third-party scripts that call home
Because the only cookies we set are strictly necessary for the service to function, no cookie consent banner is required under GDPR / ePrivacy.
10. Breach notification
If we become aware of a personal data breach affecting your data, we will notify the relevant supervisory authority within 72 hours as required by GDPR Art. 33 and, where the breach is likely to result in a high risk to you, notify you directly without undue delay (GDPR Art. 34).
11. Children
Sheaf is not intended for users under 16 years of age (see Terms, §4). Accounts suspected to belong to users below this age will be suspended.
12. Changes
Material changes to this policy are announced through the notice mechanism described in Terms §14: an in-app banner and an email to account owners, with at least 14 days notice before the change takes effect. A change is material if it changes what we collect, what we do with it, how long we keep it, or who processes it.
Non-material changes just update the effective date at the top.
13. Contact
Privacy questions, data requests, or complaints: [email protected]. See /legal/ for company details.