Subprocessors
Effective: 2026-09-16.
To run the hosted Sheaf instances, Lupine Systems LLC uses the third-party service providers ("subprocessors") listed below. This page is the canonical, up-to-date list referenced by the Privacy Policy.
User-configured integrations such as Pushover, ntfy, or generic webhooks are not subprocessors of Lupine Systems — they are third-party destinations you choose to send data to, governed by their own terms. See Privacy Policy §5.1.
Current subprocessors
| Subprocessor | Purpose | Data processed | Location | DPA in place |
|---|---|---|---|---|
| Amazon Web Services (AWS) | Application hosting (EC2), database (RDS and/or selfhosted on EC2), object storage (S3), cache (ElastiCache and/or selfhosted on EC2), secrets management (Secrets Manager), encrypted backups, and transactional email via Amazon SES (verification, password reset, notifications) with bounce/complaint handling | Encrypted account and system data, uploaded images, operational logs, encrypted credentials, and for email: recipient addresses, message contents, delivery events | eu-west-1, email included (backups remain in EU - see Privacy §6) | AWS GDPR DPA (auto-executed under AWS Service Terms) |
| Cloudflare | Normal mode: CDN/caching for images served from our S3 origin. DDoS mode: manually enabled (operator script) under active attack; full-traffic proxying with WAF and Turnstile (CAPTCHA), signposted by an in-app banner and on the status channels listed in Terms §3b. An account-level opt-out is available - opted-out users cannot log in while DDoS mode is on. | Image request metadata (IP, URL, headers) in normal mode; TLS-terminated request/response content in DDoS mode | Global edge network (US-headquartered; traffic routed to nearest edge) | Cloudflare DPA (auto-executed under Cloudflare's self-serve subscription agreement) |
How to get notified of changes
Adding a subprocessor, or replacing one with a company not already on this list, is a material change. It is announced through the notice mechanism in Terms §14 (in-app banner and email to account owners) with at least 14 days notice, and recorded below, so that anyone who objects has time to export their data and close their account before it takes effect.
Removing a subprocessor, or moving work onto one already listed here, does not send your data anywhere new. Those are recorded below when they happen, without a notice period.
If a change has to happen urgently, because a provider fails, terminates service, or becomes a security risk, we may act first and tell you as soon as we practically can rather than sitting on a broken service for two weeks. We would rather commit to a notice period we can actually keep and name the exception honestly than promise one we would have to quietly break.
Historical changes
2026-09-16 - Transactional email moved from Twilio SendGrid to Amazon SES. Twilio SendGrid has been removed as a subprocessor. All transactional email (address verification, password reset, notification delivery) and its bounce/complaint handling now runs on Amazon SES in eu-west-1, under the existing AWS relationship above.
No new subprocessor was introduced: this consolidates onto a provider already on this list, and it moves outbound email processing from the United States into the EU region where the rest of the infrastructure already sits. Email delivery is consequently no longer a routine international transfer, and Privacy §6 has been updated to match.