Privacy
How personal data reaches Sheaf, what happens to it here, how long it stays, and what you can require of us.
Who this covers
This policy is published by Sheaf Software Services, a Delaware corporation, registered office 1007 N. Orange Street, 4th Floor, Wilmington, DE 19801, United States, referred to here as Sheaf. It covers the Sheaf application, this website, and any evaluation carried out before a contract is signed.
Two different relationships are in play, and the distinction matters for your rights. For account data — the people who log in and use Sheaf — we are the controller. For document content uploaded by a customer, we are a processor acting on that customer's instructions, and the customer is the controller. If your personal data appears inside a document somebody uploaded, your relationship is with them, and we will support them in responding to you.
What we collect
- Account data Name, work email, organization, role, and authentication records for the people who use the product.
- Document content The files a customer uploads, everything they contain, and the values extracted from them. This routinely includes personal and financial data belonging to third parties.
- Usage and audit records Actions taken in the product, including who decided what and when, because that record is a product feature and not only a log.
- Technical data Request metadata needed to operate and secure the service. Website analytics: none. This site loads no third-party analytics, advertising or tracking scripts, and sets no cookies.
Why we process it
Account data is processed to provide the service and on the basis of our legitimate interest in operating it securely. Document content is processed solely to perform the work the customer asked for, under their instructions and under the contract with them. Audit records are retained because the product's purpose requires a defensible trail. Our full lawful-basis table is at available on request from privacy@sheaf.us.
Model processing
Reading a document involves model inference carried out by named subprocessors. Customer document content is not used to train models, ours or anyone else's. The current subprocessor list, and the regions in which processing occurs, is at available on request from privacy@sheaf.us, and we will give 30 days' notice before adding one.
How long we keep it
Document data is retained on a fixed window and swept automatically when it expires; the default window is 12 months, and customers may contract for a shorter one. Account data is kept for the life of the account and 90 days thereafter. Audit records follow a 24-month retention window.
Who else sees it
Subprocessors as listed above, and nobody else, other than where we are compelled by law. We do not sell personal data, and we do not share it for advertising. Where a disclosure is legally compelled we will notify the customer unless prohibited from doing so.
Your rights
Depending on where you are, you may have the right to access, correct, delete, port, or restrict the processing of your personal data, and to object to it. Where we act as processor, requests are routed to the customer who controls the data, and we will tell you who that is where we are permitted to.
Requests go to privacy@sheaf.us and are answered within 30 days. If you are unsatisfied, you may complain to your supervisory authority; ours is the Irish Data Protection Commission for processing subject to the EU GDPR, and the UK Information Commissioner's Office for processing subject to the UK GDPR.
International transfers
Where data moves between jurisdictions we rely on the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where the UK GDPR applies. Details of the safeguards, and copies of the relevant clauses, are available at privacy@sheaf.us on request.
Security
Access is checked against the requesting role on every request, records age out on a fixed window, and every extracted value stays traceable to the page it was read from. Our posture, including certification status, is set out on security and data handling.
Changes
Material changes will be notified by email to the account's registered administrators and by a notice on this page at least 30 days in advance. This page was last updated on 30 August 2026.
Sheaf