Sheaf

Hosted Service Terms of Service

Sheaf — Hosted Instances

Published and effective: 2026-09-18.

What changed, and why there is no waiting period. This revision clarifies existing terms rather than extending what we may do with your data, so it takes effect immediately under §14. We are announcing it anyway, because you should not have to diff a legal document to find out something moved.

Nothing here takes away a right you had, permits anything we could not already do, or changes where your data goes. If we had read it as doing any of those, you would be getting 14 days notice and this would say so.

These Terms govern your use of the hosted Sheaf instances operated by Lupine Systems LLC — specifically app.sheaf.sh (production) and test.sheaf.sh (public test instance). Self-hosted instances of Sheaf are not covered by these Terms; they are governed by whoever operates that instance.

Production and Test instances app.sheaf.sh is the production instance: it is the real one, intended for your actual data, and §3b sets out what we commit to for it. test.sheaf.sh is a sandbox for testing and evaluation, it is unstable by design, and data on it may be wiped at any time without notice (§3c). If you are here to use Sheaf, you want app.sheaf.sh.

1. Parties

2. Acceptance of Terms

By creating an account or using the Service, you agree to these Terms. If you do not agree, please do not use it.

3. Nature of the Service

We operate two instances, and which one you are on determines what you can expect from it.

Sections 4 to 17 apply equally to both. §3b is production-specific and §3c is test-specific. The two instances are independent of each other, and an account on one is not an account on the other (see §14).

Whichever you use, we strongly recommend keeping independent backups of anything you would be upset to lose. Sheaf supports full data export, including image bytes, and the export imports back as-is. Use it.

3b. Production Instance (app.sheaf.sh)

The production instance at app.sheaf.sh is the long-running, real-data instance. The following apply to it in addition to Sections 4–17.

3c. Test Instance (test.sheaf.sh)

The sandbox at test.sheaf.sh exists so you can try Sheaf, reproduce a bug, or test an integration without touching anything you care about. None of the §3b commitments apply to it. Specifically:

All data uploaded to a test instance is deleted whenever the instance is reset, rebuilt, or discontinued.

4. Eligibility

You must be at least 16 years of age to use the Service, and legally able to enter into a contract in your jurisdiction. Accounts suspected to belong to users below this age will be suspended.

Publishing a public profile or share link (§7.1) additionally requires you to be at least 18, and you will be asked to confirm that once before anything can be made visible. We record that confirmation as a simple yes or no, with a timestamp; we do not ask for your date of birth and do not collect identity documents. The higher bar applies to publishing to people outside your system, not to using the Service.

5. Your Account

You are responsible for maintaining the security of your account credentials and for all activity that occurs under your account. Please use a password unique to this Service, and a separate one again for the test instance. Enable 2FA. Tell us immediately if you believe your account has been compromised.

Accounts may be suspended or removed for violations of these Terms, and test-instance accounts additionally disappear whenever that instance is reset (§3c).

6. Acceptable Use

You agree not to use the Service to:

This is a small community-focused project. Please be a reasonable person.

Responsible disclosure

If you discover a security vulnerability, please report it responsibly. We welcome disclosure via GitHub Security Advisories, by emailing [email protected], or by contacting a maintainer privately via the official Discord. See also the project's SECURITY.md.

7. Your Content

You retain all rights to content you upload or create in the Service: members, fronts, files, custom fields, and so on. By submitting content, you grant us a limited, non-exclusive, non-transferable, royalty-free licence solely to operate the Service for you: to store it, display it back to you, process it for features you've enabled, and back it up.

That licence exists only so the Service can function. It grants us no right to use your content for anything else.

We do not sell your data, advertise against it, or share it with third parties except as required to run the Service (see the Subprocessors list) or as required by law (see §10).

If, and only if, you choose to publish part of your system using public profiles or share links, you additionally grant us the licence needed to do what you have asked: to publicly display and transmit that content to whoever can reach the address you created, and to make the technical copies that serving a web page requires, such as caching.

This extension is deliberately narrow:

Two things we cannot undo for you, and would rather say plainly than bury:

Content you publish remains subject to §6. We may withdraw published content, and may prevent a system from publishing further, where it breaches §6 or where we are required to act on a report, independently of any action on your account.

Please do not submit content that you consider irreplaceable without keeping your own copy of it, and please treat anything on the test instance (§3c) as disposable.

8. Plans and Billing

The Service is currently free. If and when paid tiers are introduced, this section will be updated.

9. Termination

You may delete your account at any time from within the Service. Deletion triggers a grace period (default of 7 days), after which all data is irrecoverably deleted. See the Privacy Policy for detail on deletion mechanics.

We may suspend or terminate your account for material breach of these Terms, or if we discontinue the Service. Where practical we'll give reasonable notice and allow you to export your data; we may decline to do so where export would enable further abuse or illegal activity.

We will comply with valid legal process. We will push back on overbroad or facially invalid requests and, where legally permitted, will notify affected users. Where legally prohibited from notifying (e.g. a gag order), we will not notify until the prohibition lapses.

We do not offer end-to-end encryption. If you need the operator to be technically unable to comply with legal requests, self-host Sheaf on infrastructure you control.

Warrant canary

We publish a warrant canary at github.com/sheaf-canary/sheaf-canary (mirror: codeberg.org/sheaf-canary/sheaf-canary). Each canary is a signed attestation, refreshed quarterly (every 90 days), that we have not received secret legal demands within the categories named in the canary itself.

Each canary includes a 14-day grace period past its due date. If it is not renewed before the grace period ends, treat it as expired and assume one or more of its assertions no longer holds. Silence is the signal. There is no duress code; the only correct response to compulsion is to decline to sign.

Canaries are signed by two independent keys (both signatures required):

The full public keys are checked into the repository under keys/ and have been uploaded to keyserver.ubuntu.com. Fingerprints are also embedded inline in each signed canary file. Because both UIDs use GitHub no-reply addresses, not every keyserver will accept them — treat the repository copy and keyserver.ubuntu.com as the canonical sources.

The quarterly cadence may be revisited annually, or changed earlier with at least 3 months' notice published in a signed canary. Unannounced schedule changes are not a valid schedule change.

On legal strength: warrant canaries are a best-effort signal, not a legal guarantee. The "absence = signal" mechanic has not been tested against a determined state actor in court. The mechanic does have some plausible footing while the operator and signatories remain in the United States, where compelling a person to re-sign a known-false attestation runs into First Amendment compelled-speech doctrine — a meaningfully higher bar than exists in jurisdictions whose statutes explicitly contemplate compelled assistance with non-disclosure (e.g. the UK Investigatory Powers Act, Australia's Assistance and Access Act). That argument is supportive, not dispositive: it is untested in this specific context, depends on continued US jurisdiction over the signatories, and offers no protection against secret demands that don't require affirmative false speech. If your threat model requires the operator to be technically unable to comply with secret legal demands, self-host Sheaf on infrastructure you control — that is the only defence we can offer with confidence.

11. Open Source Software

The Software is free and open source, licensed under the GNU Affero General Public License v3.0 (AGPL-3.0). The source code is available at github.com/sheaf-project. These Terms govern your use of instances of the Software connected to the project itself or otherwise run by Lupine Systems LLC; the AGPL governs your rights with respect to your personal use of the Software itself.

12. Disclaimers and Limitation of Liability

THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, OR AVAILABILITY.

TO THE MAXIMUM EXTENT PERMITTED BY LAW, LUPINE SYSTEMS LLC AND ITS OPERATORS SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, INCLUDING LOSS OF DATA, LOSS OF PROFIT, LOSS OF GOODWILL, OR BUSINESS INTERRUPTION, ARISING FROM YOUR USE OF THE SERVICE.

TO THE MAXIMUM EXTENT PERMITTED BY LAW, OUR AGGREGATE LIABILITY TO YOU FOR ANY CLAIM ARISING FROM OR RELATED TO THE SERVICE IS LIMITED TO THE GREATER OF USD $100 OR THE AMOUNT YOU PAID US IN THE 12 MONTHS PRECEDING THE CLAIM.

Some jurisdictions do not allow these limitations; to the extent they don't, the limitations apply to the maximum extent they are permitted.

For the test instance specifically, you acknowledge that data loss is an expected and foreseeable outcome, and waive any claim for damages arising from it.

In plain English: we run production carefully and back it up, but we are a small project offering it free and without an SLA, so keep your own export of anything you would be upset to lose. On the test instance, assume it will be wiped, because eventually it will.

13. Indemnification

You agree to indemnify us against claims arising from (i) your content, (ii) your violation of these Terms, or (iii) your violation of any applicable law or third-party right. This does not cover claims caused by us.

14. Changes to These Terms

We may update these Terms at any time. Continued use of the Service after a change takes effect constitutes acceptance of the updated Terms.

How we notify you

This is the notice mechanism for the hosted service. The Privacy Policy and Subprocessors list use it too, so there is one description of it rather than three that drift apart.

A change is material if it changes your rights, what we do with your data, or who processes it. For a material change to the production instance:

If you don't agree with a change, your remedy is to delete your account before it takes effect.

For non-material changes (clarifications, corrections, rewording that does not alter what we may do), the Published and Effective dates are the same and there is no waiting period or email. We may still mention a clarification in the app or on Discord where it is worth knowing about, and we would rather over-explain a change than have you find it by diffing the page. Doing so does not make it a material change, and does not oblige us to do it for every typo.

We also post about changes to the project Discord and the social accounts listed in §3b. Those are best-effort and are not the notice mechanism: they are not guaranteed, they may be skipped for routine updates, and you should not rely on them to learn about a change. The page itself, with its dates, is the canonical record.

For the test instance, we may make changes without advance notice.

The two instances are independent. An account on one is not an account on the other, and test-instance data does not carry over. Signing up on app.sheaf.sh is a fresh acceptance of the Terms then in force (including §3b). Test-instance accounts continue under these Terms until that instance is reset, rebuilt, or discontinued, at which point they are deleted per §9.

This page carries two dates: Published, when the text was put up, and Effective, when it starts binding. Where a change needs notice, those dates differ and the previous version stays in force until the effective date arrives. For changes that need no notice, they are the same date.

15. Governing Law

These Terms are governed by the laws of the State of Connecticut, United States, without regard to its conflict of law provisions.

Any disputes arising out of or relating to these Terms or your use of the service shall be resolved in the courts of the State of Connecticut. You consent to the exclusive jurisdiction of those courts.

16. Miscellaneous

17. Contact

Questions about these Terms: [email protected], or via the project's GitHub organisation at github.com/sheaf-project. Formal legal notices should be addressed to the registered agent listed at /legal/.