Hosted Service Terms of Service
Sheaf — Hosted Instances
Published and effective: 2026-09-18.
What changed, and why there is no waiting period. This revision clarifies existing terms rather than extending what we may do with your data, so it takes effect immediately under §14. We are announcing it anyway, because you should not have to diff a legal document to find out something moved.
- §7.1 spells out the content licence for public profiles and share links. The previous wording already licensed us to "process it for features you've enabled", and publishing is a feature you enable by a deliberate act, per item. §7.1 says plainly what that involves, and bounds it: triggered only by you, scoped to what you published, ended by revoking, transferred to nobody.
- §4 records that publishing requires you to be 18 or older. The app has always enforced this; it simply was not written down here.
- Everything else removes text that described the whole Service as a pre-release test environment, which stopped being true when
app.sheaf.shlaunched, and separates what we commit to for production (§3b) from the caveats that apply to the sandbox (§3c).
Nothing here takes away a right you had, permits anything we could not already do, or changes where your data goes. If we had read it as doing any of those, you would be getting 14 days notice and this would say so.
These Terms govern your use of the hosted Sheaf instances operated by Lupine Systems LLC — specifically app.sheaf.sh (production) and test.sheaf.sh (public test instance). Self-hosted instances of Sheaf are not covered by these Terms; they are governed by whoever operates that instance.
app.sheaf.sh is the production instance: it is the real one, intended for your actual data, and §3b sets out what we commit to for it. test.sheaf.sh is a sandbox for testing and evaluation, it is unstable by design, and data on it may be wiped at any time without notice (§3c). If you are here to use Sheaf, you want app.sheaf.sh.
1. Parties
- "You" or "User" — the person or legal entity registering an account.
- "We", "us", "Sheaf" — Lupine Systems LLC, contact details on /legal/.
- "the Software" — the open-source Sheaf application at github.com/sheaf-project.
- "the Service" - the specific instance(s) we operate at
app.sheaf.shandtest.sheaf.sh.
2. Acceptance of Terms
By creating an account or using the Service, you agree to these Terms. If you do not agree, please do not use it.
3. Nature of the Service
We operate two instances, and which one you are on determines what you can expect from it.
app.sheaf.shis the production instance. It is intended for real use with real data. §3b sets out what we commit to.test.sheaf.shis a public sandbox. It exists for trying things out and chasing bugs, and nothing on it is durable. §3c sets out the caveats.
Sections 4 to 17 apply equally to both. §3b is production-specific and §3c is test-specific. The two instances are independent of each other, and an account on one is not an account on the other (see §14).
Whichever you use, we strongly recommend keeping independent backups of anything you would be upset to lose. Sheaf supports full data export, including image bytes, and the export imports back as-is. Use it.
3b. Production Instance (app.sheaf.sh)
The production instance at app.sheaf.sh is the long-running, real-data instance. The following apply to it in addition to Sections 4–17.
- Availability is best-effort. We do not offer a Service Level Agreement (SLA), uptime guarantee, or service credit. We run the production instance with the operational care you'd expect from people whose day job is running production systems, but the Service is provided "as available." Planned maintenance, infrastructure migrations, and incident recovery may cause outages.
- Backups are taken and retained. The production database is regularly captured into encrypted backups; copies persist for a minimum of 7 and a maximum of 30 days, after which they are overwritten. Backups are encrypted asymmetrically with the decryption key held offline. See the Privacy Policy §4 for detail.
- Account-deletion retention. Self-service account deletion triggers a 7-day grace period (cancellable from your account), after which all live-database data is irrecoverably deleted. Backup copies age out per the rotation above.
- Support is best-effort. Reach us at [email protected] or via the project's Discord. We do not offer guaranteed response times. We read everything and will get back to you; we just won't pretend it's an SLA.
- No paid tier at launch. The Service is free at launch. If a paid tier is introduced in future, §8 will be updated and material changes announced per §14.
- Status updates. Service status, planned maintenance, and incident communication are posted to the project Discord, Fediverse/Mastodon, Bluesky, Tumblr, X, and the project subreddit. A dedicated status page is planned.
3c. Test Instance (test.sheaf.sh)
The sandbox at test.sheaf.sh exists so you can try Sheaf, reproduce a bug, or test an integration without touching anything you care about. None of the §3b commitments apply to it. Specifically:
- Availability is not guaranteed. It may go down at any time, for any duration, with or without notice.
- Data persistence is not guaranteed. Anything you put on it, including account information, member profiles, and fronting history, may be deleted or reset at any time without warning, and is not covered by the backup commitments in §3b.
- Features may be incomplete or may change, since it is where changes get tried before they reach production. There may be breaking changes, undocumented behaviour, and similar. While we will wherever possible make sure the test instance has a linkable commit on GitHub to inspect the source code, this is not guaranteed, and we may deploy private builds to this instance if we deem it necessary.
- Security Considerations: The test instance has near-production-level security using the same encryption and security model, but is not guaranteed to be completely equivalent, and new features are not guaranteed to have been fully tested and confirmed secure. Users should make their own informed decision about importing their data from the production instance.
- Do not use it as your only record of anything. Treat everything on it as disposable, and use a password unique to it.
All data uploaded to a test instance is deleted whenever the instance is reset, rebuilt, or discontinued.
4. Eligibility
You must be at least 16 years of age to use the Service, and legally able to enter into a contract in your jurisdiction. Accounts suspected to belong to users below this age will be suspended.
Publishing a public profile or share link (§7.1) additionally requires you to be at least 18, and you will be asked to confirm that once before anything can be made visible. We record that confirmation as a simple yes or no, with a timestamp; we do not ask for your date of birth and do not collect identity documents. The higher bar applies to publishing to people outside your system, not to using the Service.
5. Your Account
You are responsible for maintaining the security of your account credentials and for all activity that occurs under your account. Please use a password unique to this Service, and a separate one again for the test instance. Enable 2FA. Tell us immediately if you believe your account has been compromised.
Accounts may be suspended or removed for violations of these Terms, and test-instance accounts additionally disappear whenever that instance is reset (§3c).
6. Acceptable Use
You agree not to use the Service to:
- Upload, store, or distribute content that is illegal under applicable law
- Upload, store, or distribute pornographic material — meaning content whose dominant purpose is sexual arousal. Non-sexualised nudity in an artistic, anatomical, gender-affirming, or body-acceptance context is not what this clause is aimed at; we'll use judgement on borderline cases and lean toward the user where intent is clearly not pornographic. The hard line is the next bullet, and it is absolute.
- Upload child sexual abuse material (CSAM) or any content that sexually exploits minors — this will result in immediate account termination and reporting to NCMEC and law enforcement
- Harass, threaten, dox, or harm other users
- Engage in bigotry or discrimination of any kind, including but not limited to racism, sexism, homophobia, transphobia, or ableism — this is a service built for a marginalised community and we have zero tolerance for it
- Engage in sysmedicalism — gatekeeping, invalidating, or denying the experiences of plural systems based on perceived origin, diagnosis, or any other criteria
- Promote authoritarian, fascist, or far-right ideologies
- Impersonate another system or person in a way intended to harm or defraud them
- Attempt to gain unauthorised access to other accounts or to the underlying infrastructure, or exploit any vulnerability for any purpose other than responsibly demonstrating it to us
- Attempt to disrupt or degrade the availability of the Service
- Evade moderation, rate limits, or abuse controls
- Resell access to the Service, or run it for the benefit of unaffiliated third parties without our permission
This is a small community-focused project. Please be a reasonable person.
Responsible disclosure
If you discover a security vulnerability, please report it responsibly. We welcome disclosure via GitHub Security Advisories, by emailing [email protected], or by contacting a maintainer privately via the official Discord. See also the project's SECURITY.md.
7. Your Content
You retain all rights to content you upload or create in the Service: members, fronts, files, custom fields, and so on. By submitting content, you grant us a limited, non-exclusive, non-transferable, royalty-free licence solely to operate the Service for you: to store it, display it back to you, process it for features you've enabled, and back it up.
That licence exists only so the Service can function. It grants us no right to use your content for anything else.
We do not sell your data, advertise against it, or share it with third parties except as required to run the Service (see the Subprocessors list) or as required by law (see §10).
7.1 Public profiles and share links
If, and only if, you choose to publish part of your system using public profiles or share links, you additionally grant us the licence needed to do what you have asked: to publicly display and transmit that content to whoever can reach the address you created, and to make the technical copies that serving a web page requires, such as caching.
This extension is deliberately narrow:
- You trigger it, every time. It applies only to content you have deliberately added to a view and then published through a grant. Nothing else you store is covered, and nothing is published by default.
- It is scoped to what you published. Adding someone to a group, or creating a view without granting it, publishes nothing.
- It ends when you say so. Revoking a grant, rotating a share link, or removing content from a view ends the licence for that content. Serving stops immediately, though a page a visitor already loaded, or an intermediate cache, may persist for a short period afterwards.
- It transfers to nobody. We do not gain any right to reuse, relicense, or promote your published content.
Two things we cannot undo for you, and would rather say plainly than bury:
- Public means public. Anyone who can reach the address can read it, and can copy, screenshot, archive, or repost it. Public profile and share-link pages ask search engines not to index them and ask browsers not to leak the address as a referrer, but neither of those stops a person or a crawler that ignores them. Revoking a link stops us serving the content; it does not reach into copies other people already made.
- A share link is a secret, and secrets travel. Anyone holding the link can open it and can pass it on. If a link reaches someone you did not intend, rotate or revoke it.
Content you publish remains subject to §6. We may withdraw published content, and may prevent a system from publishing further, where it breaches §6 or where we are required to act on a report, independently of any action on your account.
Please do not submit content that you consider irreplaceable without keeping your own copy of it, and please treat anything on the test instance (§3c) as disposable.
8. Plans and Billing
The Service is currently free. If and when paid tiers are introduced, this section will be updated.
9. Termination
You may delete your account at any time from within the Service. Deletion triggers a grace period (default of 7 days), after which all data is irrecoverably deleted. See the Privacy Policy for detail on deletion mechanics.
We may suspend or terminate your account for material breach of these Terms, or if we discontinue the Service. Where practical we'll give reasonable notice and allow you to export your data; we may decline to do so where export would enable further abuse or illegal activity.
10. Law Enforcement and Legal Requests
We will comply with valid legal process. We will push back on overbroad or facially invalid requests and, where legally permitted, will notify affected users. Where legally prohibited from notifying (e.g. a gag order), we will not notify until the prohibition lapses.
We do not offer end-to-end encryption. If you need the operator to be technically unable to comply with legal requests, self-host Sheaf on infrastructure you control.
Warrant canary
We publish a warrant canary at github.com/sheaf-canary/sheaf-canary (mirror: codeberg.org/sheaf-canary/sheaf-canary). Each canary is a signed attestation, refreshed quarterly (every 90 days), that we have not received secret legal demands within the categories named in the canary itself.
Each canary includes a 14-day grace period past its due date. If it is not renewed before the grace period ends, treat it as expired and assume one or more of its assertions no longer holds. Silence is the signal. There is no duress code; the only correct response to compulsion is to decline to sign.
Canaries are signed by two independent keys (both signatures required):
- SiteRelEnby —
0315 B758 2C0B 170D E1C1 AC48 722E B40A DED7 99AE - Nocturnal —
3C12 5C08 0C7E 92BF 848C CD16 7B09 9825 CFE4 2493
The full public keys are checked into the repository under keys/ and have been uploaded to keyserver.ubuntu.com. Fingerprints are also embedded inline in each signed canary file. Because both UIDs use GitHub no-reply addresses, not every keyserver will accept them — treat the repository copy and keyserver.ubuntu.com as the canonical sources.
The quarterly cadence may be revisited annually, or changed earlier with at least 3 months' notice published in a signed canary. Unannounced schedule changes are not a valid schedule change.
On legal strength: warrant canaries are a best-effort signal, not a legal guarantee. The "absence = signal" mechanic has not been tested against a determined state actor in court. The mechanic does have some plausible footing while the operator and signatories remain in the United States, where compelling a person to re-sign a known-false attestation runs into First Amendment compelled-speech doctrine — a meaningfully higher bar than exists in jurisdictions whose statutes explicitly contemplate compelled assistance with non-disclosure (e.g. the UK Investigatory Powers Act, Australia's Assistance and Access Act). That argument is supportive, not dispositive: it is untested in this specific context, depends on continued US jurisdiction over the signatories, and offers no protection against secret demands that don't require affirmative false speech. If your threat model requires the operator to be technically unable to comply with secret legal demands, self-host Sheaf on infrastructure you control — that is the only defence we can offer with confidence.
11. Open Source Software
The Software is free and open source, licensed under the GNU Affero General Public License v3.0 (AGPL-3.0). The source code is available at github.com/sheaf-project. These Terms govern your use of instances of the Software connected to the project itself or otherwise run by Lupine Systems LLC; the AGPL governs your rights with respect to your personal use of the Software itself.
12. Disclaimers and Limitation of Liability
THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, OR AVAILABILITY.
TO THE MAXIMUM EXTENT PERMITTED BY LAW, LUPINE SYSTEMS LLC AND ITS OPERATORS SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, INCLUDING LOSS OF DATA, LOSS OF PROFIT, LOSS OF GOODWILL, OR BUSINESS INTERRUPTION, ARISING FROM YOUR USE OF THE SERVICE.
TO THE MAXIMUM EXTENT PERMITTED BY LAW, OUR AGGREGATE LIABILITY TO YOU FOR ANY CLAIM ARISING FROM OR RELATED TO THE SERVICE IS LIMITED TO THE GREATER OF USD $100 OR THE AMOUNT YOU PAID US IN THE 12 MONTHS PRECEDING THE CLAIM.
Some jurisdictions do not allow these limitations; to the extent they don't, the limitations apply to the maximum extent they are permitted.
For the test instance specifically, you acknowledge that data loss is an expected and foreseeable outcome, and waive any claim for damages arising from it.
In plain English: we run production carefully and back it up, but we are a small project offering it free and without an SLA, so keep your own export of anything you would be upset to lose. On the test instance, assume it will be wiped, because eventually it will.
13. Indemnification
You agree to indemnify us against claims arising from (i) your content, (ii) your violation of these Terms, or (iii) your violation of any applicable law or third-party right. This does not cover claims caused by us.
14. Changes to These Terms
We may update these Terms at any time. Continued use of the Service after a change takes effect constitutes acceptance of the updated Terms.
How we notify you
This is the notice mechanism for the hosted service. The Privacy Policy and Subprocessors list use it too, so there is one description of it rather than three that drift apart.
A change is material if it changes your rights, what we do with your data, or who processes it. For a material change to the production instance:
- An in-app banner on
app.sheaf.shruns for the notice period. This is the channel we consider binding on ourselves, because it is the one we control end to end. - An email goes to account owners. This is a contractual notice rather than marketing, so it is sent regardless of whether you have opted into update emails, and there is no way to switch it off short of closing your account. We keep this for material changes specifically, so that an email from us stays a rare thing that is worth opening.
- At least 14 days notice before it takes effect, so the page will carry a Published date and a later Effective date.
- Where a change needs more explanation than a banner holds, the notice links to a written summary.
If you don't agree with a change, your remedy is to delete your account before it takes effect.
For non-material changes (clarifications, corrections, rewording that does not alter what we may do), the Published and Effective dates are the same and there is no waiting period or email. We may still mention a clarification in the app or on Discord where it is worth knowing about, and we would rather over-explain a change than have you find it by diffing the page. Doing so does not make it a material change, and does not oblige us to do it for every typo.
We also post about changes to the project Discord and the social accounts listed in §3b. Those are best-effort and are not the notice mechanism: they are not guaranteed, they may be skipped for routine updates, and you should not rely on them to learn about a change. The page itself, with its dates, is the canonical record.
For the test instance, we may make changes without advance notice.
The two instances are independent. An account on one is not an account on the other, and test-instance data does not carry over. Signing up on app.sheaf.sh is a fresh acceptance of the Terms then in force (including §3b). Test-instance accounts continue under these Terms until that instance is reset, rebuilt, or discontinued, at which point they are deleted per §9.
This page carries two dates: Published, when the text was put up, and Effective, when it starts binding. Where a change needs notice, those dates differ and the previous version stays in force until the effective date arrives. For changes that need no notice, they are the same date.
15. Governing Law
These Terms are governed by the laws of the State of Connecticut, United States, without regard to its conflict of law provisions.
Any disputes arising out of or relating to these Terms or your use of the service shall be resolved in the courts of the State of Connecticut. You consent to the exclusive jurisdiction of those courts.
16. Miscellaneous
- Severability — if any provision is held unenforceable, the rest remains in effect.
- No waiver — a failure to enforce a right doesn't waive it.
- Assignment — you may not assign these Terms without our consent; we may assign them in connection with a reorganisation or sale of the business.
- Entire agreement — these Terms, together with the Privacy Policy and Subprocessors list, are the entire agreement between us regarding the Service.
17. Contact
Questions about these Terms: [email protected], or via the project's GitHub organisation at github.com/sheaf-project. Formal legal notices should be addressed to the registered agent listed at /legal/.