Sheaf

Hosted Service Privacy Policy

Effective: 2026-09-16.

This policy covers the hosted instances of Sheaf operated by Lupine Systems LLC at app.sheaf.sh (production) and test.sheaf.sh (public test instance). Self-hosted instances are outside its scope.

For privacy relating to the marketing site sheaf.sh itself, see /privacy/.

1. Data controller

Lupine Systems LLC. See /legal/ for full company identification and contact details.

2. What we collect

2.1 Account data

2.2 System data

Anything you enter into Sheaf: members, fronting history, groups, tags, custom fields, avatars, uploaded files, etc. This is treated as GDPR Article 9 special category data (data revealing information about health or identity).

2.3 Operational logs and metrics

2.4 Security event log

To detect credential-stuffing and other account-abuse attacks - one IP failing logins against many accounts, an account being hammered with reset requests, a sign-in from an unexpected place - we keep a short, append-only log of authentication events tied to your account:

This is distinct from the operational HTTP logs in §2.3: it is account-linked and exists specifically for abuse detection and incident investigation, under the legitimate-interest basis in §3. Failed logins against an address that was never registered are recorded against the IP only - we do not store the attempted email. Administrative actions on your account additionally record the acting administrator's IP.

The security event log is retained for a maximum of 30 days (the default; the window is configurable per instance) and then purged. It is included in your data export and in any access request.

2.5 Payment data (if applicable)

If you subscribe to a paid tier, payment information is handled directly by our payment processor. We receive only: last-four of card, billing country, subscription status. We do not see or store full card numbers.

Purpose Legal basis
Providing the service (account, member and front tracking, etc.) Art. 6(1)(b) — performance of contract
Processing Article 9 data (members, fronts, identity-related fields) Art. 9(2)(a) — explicit consent
Security, abuse prevention, logging Art. 6(1)(f) — legitimate interest
Billing and tax records Art. 6(1)(c) — legal obligation
Email for account notifications Art. 6(1)(b) — performance of contract

4. How long we keep it

Once the grace period elapses, your account and all associated data are deleted from the live database. Copies persist in encrypted backups for a minimum of 7 days and a maximum of 30 days, after which they are overwritten in the normal course of rotation. After that point the data is gone from our systems.

Backups are encrypted asymmetrically: the public encryption key lives on the backup-writing infrastructure, while the private decryption key is held offline and is required to read a backup at all. This means an attacker who compromises the live infrastructure cannot read historical backups, and a backup leak in isolation discloses only ciphertext.

5. Subprocessors

We use third parties to run the service. See /service/subprocessors/ for the canonical, up-to-date list.

5.1 User-configured integrations

If you connect Sheaf to a third-party notification destination (such as Pushover, ntfy, a generic webhook, or any future integration of this kind), data flows from the hosted instance to that destination as you direct it. Those third parties are not subprocessors of Lupine Systems — we don't engage them on our own behalf; you do, by configuring the integration — but the data still reaches them, and their own terms and privacy policies govern what they do with it. You are the controller of that flow; we are the conduit.

Disable any such integration in Settings to stop the flow. Removing the integration also clears the credentials we hold for it.

6. International transfers

Primary infrastructure for the hosted Sheaf instances runs in the European Union, on AWS in eu-west-1 (Ireland). EC2 compute, the primary database, object storage, and encrypted backups all stay within the EU. No bulk replication of personal data outside the EU takes place.

Transactional email is sent via Amazon SES in the same eu-west-1 region, so composing, sending, and bounce/complaint handling all happen inside the EU. (Once a message leaves for the recipient's own mail provider, it is subject to wherever that provider operates, which is inherent to email and outside anyone's control but the recipient's.)

One category of routine transfer occurs via subprocessors (see /service/subprocessors/):

Where these transfers involve EU personal data being processed outside the EU, we rely on:

UK → non-UK transfers rely on the UK Addendum to the SCCs and the UK extension to the Data Privacy Framework on the same basis.

7. Your rights

Under GDPR, UK GDPR, CCPA/CPRA and comparable laws you have the right to:

Where your jurisdiction does not grant you these rights as a matter of law, we extend them as a matter of policy: anyone may exercise the rights set out above by contacting us, regardless of where they are. Practical limitations apply only where retention is required by law that does bind us (e.g. billing records under US tax law). The "complain to a supervisory authority" right is the one exception, since it depends on a supervisory authority you can complain to actually existing in your jurisdiction.

To exercise any right that isn't handled in-app, email [email protected].

8. Security

Summary (full detail in the Sheaf repo):

No system is perfectly secure. See §10 for what happens if something goes wrong.

Responsible disclosure: [email protected], GitHub Security Advisories, or the project's SECURITY.md.

9. Cookies and tracking on the hosted app

The hosted app sets two cookies, both strictly necessary to operate it:

Both are first-party, HttpOnly where applicable, Secure, and SameSite=Lax or stricter. They are cleared when you log out.

We do not use:

Because the only cookies we set are strictly necessary for the service to function, no cookie consent banner is required under GDPR / ePrivacy.

10. Breach notification

If we become aware of a personal data breach affecting your data, we will notify the relevant supervisory authority within 72 hours as required by GDPR Art. 33 and, where the breach is likely to result in a high risk to you, notify you directly without undue delay (GDPR Art. 34).

11. Children

Sheaf is not intended for users under 16 years of age (see Terms, §4). Accounts suspected to belong to users below this age will be suspended.

12. Changes

Material changes to this policy are announced through the notice mechanism described in Terms §14: an in-app banner and an email to account owners, with at least 14 days notice before the change takes effect. A change is material if it changes what we collect, what we do with it, how long we keep it, or who processes it.

Non-material changes just update the effective date at the top.

13. Contact

Privacy questions, data requests, or complaints: [email protected]. See /legal/ for company details.