What we hold, why we are allowed to hold it, and how to make us stop.
This policy is for everyone: recruiters and developers who sign in, and everybody else, who gets the shortest section because there is the least to say. The Recruiter Terms of Service and the Developer Terms of Service are the agreements for each side; this document is the one both of them point at for what we hold.
Table of contents
- 1. Three kinds of people this policy is about
- 2. For developers
- 3. For everyone who signs in
- 4. Cookies
- 5. Data storage and security
- 6. Service providers we rely on
- 7. Who we are, and how to complain
- 8. Changes to this policy
- 9. Questions
1. Three kinds of people this policy is about
Account holders - anybody who signs in: recruiters, who pay for Thleo, and developers, who made a developer account. For everyone who signs in applies to both.
Developers - people with a public GitHub account who made a Thleo developer account. Whether we may show their profile to recruiters, to anyone with the link, or to nobody at all is their choice, made on their Account page. Your section comes first, because it is the one that is usually hardest to find.
Everybody else, and this is the whole of what we have to say to you: we hold nothing about you. If you have never made a Thleo developer account, your GitHub profile is not in our database, is not shown to any recruiter, and is not counted in any figure we keep. There is no setting for you to find and nothing for you to opt out of. One string can still name you: if a recruiter saves one of your public repositories, its record carries the repository's name, which GitHub spells as your username and the repository's - the same text as its address on GitHub - and nothing else about you. If that is you, the rest of this section is about somebody else. The removal page explains it in more words, and if you would rather have it from us in writing, write to us and we will confirm it in writing.
2. For developers
Thleo is a platform for technical recruiters - search, shortlists, notes, a hiring pipeline and the workflow around them - with GitHub as its only source of developer data. We show, count and store a developer's profile only with that developer's consent, and we check that consent on every read rather than at the moment we first got it.
That means all three of these must be true at once before anything about you exists here:
- you made a Thleo developer account, with your own GitHub sign-in;
- you set yourself findable - Visible to recruiters or Public. A new account starts Hidden, and changing that is your choice, on your Account page;
- you ticked the recruitment authorization box and saved it, on the version of that wording in force today. A receipt for wording we have since replaced stops counting, and you are asked again.
Miss any one and a recruiter searching your username is told there is no profile here - the same answer they get for a username that never existed on GitHub, with no hint that anybody made a choice. Nothing is displayed, and nothing new is written down. If all three were true for you once and then stopped, How long we keep it says what happens to what we already had - it depends on which one stopped.
Four things follow, and they are the shape of everything below:
- Nothing is crawled. We do not index GitHub, we do not bulk-import, and we do not buy data. Every profile we hold exists because the person it describes told us it may.
- Nothing comes from anywhere else. Not brokers, not other sites, not scraped pages. GitHub's API, and only GitHub's API.
- Nothing private is visible to us, with one named exception. GitHub gives us what it gives any visitor to your profile page, plus the email address on your account, which sign-in reads so that we can run the account and tell you about new versions of these documents. That address is on your sign-in record and is never shown to anyone. Private repositories, other private profile fields and private activity are not returned to us and we could not display them if we wanted to.
- Public means public. Visible to recruiters shows you to signed-in recruiters only, ever.
Public does the same and also serves a page at
thleo.app/developers/your-usernamethat anyone with the link can open without signing in. It shows exactly what a recruiter sees, under the same boxes, and nothing more; it never re-reads GitHub; it is reachable only by your exact username, listed nowhere, and marked not to be indexed by search engines. Because anyone can open it, it is rate-limited by the visitor's IP address - the one place this product handles the IP address of somebody who is not signed in, and it is kept only as a short-lived counter (Service providers).
2.1 What we hold about you
Written out field by field rather than summarised, because the whole point is that you can check the claim. A vague list is indistinguishable from a list that is hiding something.
Copied from your public GitHub profile
- Your username, your numeric GitHub account id, and the link to your profile
- The usernames you used before, if you changed yours on GitHub after we first saw you, with the date of each change. A recruiter who had already saved or searched you under one of them still finds you under your current username; anybody else who searches an old username of yours is told there is no profile, as GitHub tells them
- Your display name, your bio, your company, and your location - whatever those fields say on GitHub
- Your avatar image URL
- Whether your profile is marked "available for hire"
- Public counts: repositories (owned and forked), gists, followers, following
- Your public organizations, and your public contribution activity
- When your GitHub account was created, and when you were last publicly active
- Whether you have a profile README - only whether, not its text. The README itself is read from GitHub each time a recruiter opens it, and is never stored here
Only once you switch it on, one box at a time
Nothing in this group exists for you until you tick its own box on your account page. Each box is a separate decision, and none of them is ticked for you.
- The website and social links you publish on GitHub - one stored copy of each link you ticked, with the date we last read it. Untick a link and we delete our copy in the same write. A link whose box is unticked is never written down here at all.
- The email address you typed on your account page, if you typed one. It is never read from GitHub: the address on your GitHub account is read at sign-in for your sign-in record (3.2) and is never copied into your profile or shown to a recruiter. This one is different from the links in one way worth knowing: unticking the Email box stops us showing the address, and clearing the box and saving is what deletes it.
From your public repositories
- The languages of each, which the figures below are worked out from
- If a recruiter saves one of your repositories: its public description as GitHub gives it - name, description, stars, topics, languages - with your username as its owner
Worked out from your public repositories
- Which programming languages you write, and in what proportion
- A "profile confidence" score describing how complete and readable your public work is
- Per-skill proficiency percentages
Created by us, about the activity around your profile
Listed separately because this part is not public GitHub information - GitHub does not publish it, and we would rather say so than let it hide inside the list above.
- How many times your username has been searched, and by how many different recruiters
- How many times you appear in recruiters' collections, and how many different workspaces hold you in one - counts only, never which recruiters or which workspaces
- When our copy of you was last read from GitHub
- A daily tally of searched usernames, kept for a short time to rank the most-searched profiles
Written by recruiters, about you
A recruiter can add their own notes and tags to a candidate in their workspace, place you in their own collections, and keep an outreach log of when they were in contact with you, through which channel, what came of it, and when they mean to follow up, in their words. That text is written by them and controlled by them; we store it for them, for their own hiring workflow, and show it back to them as a line on your card and as dates on their own calendar. The log records the recruiter's own actions: a channel in it is a label such as "LinkedIn", never an address of yours.
Your profile is also copied into two of their records, which matters when you delete it:
- their search history - a second copy of your name, bio, location, avatar, company and "available for hire" flag, kept so their history list renders without looking you up again;
- any repository they saved that you contributed to, if you were authorized at the time they saved it. A repository saved while you were not authorized carries nothing about you.
Those copies are ours, not theirs, and deleting your data clears every one of them. What stays is described under Your rights.
2.2 What we never hold
Every line here is a thing the system genuinely cannot produce, not a promise about intent.
- Any email address in your profile that you did not type in yourself. The address on your GitHub account is on your sign-in record, to run your account and to tell you about new versions of these documents (For everyone who signs in); it is never shown to a recruiter and never copied into your profile. The only address a recruiter can see is the one you put in the box.
- Your phone number, your postal address, or any other way of reaching you that you did not give us. We read contact details from one place only - your own GitHub profile - and we store one only after you tick its box. One honest edge: if you wrote a phone number or an address into your profile README yourself, a recruiter who opens the README sees it, live from GitHub. We do not store the README and we do not read it for contact details, but we cannot unpublish what you put there.
- Any link or social account whose box you have not ticked. Not stored, not hidden, not marked withheld: a link you have not switched on is not written down here at all.
- Anything at all from private repositories, private profile fields, or private activity.
None of it is on by default, and each one is its own decision. The only route a recruiter gets from us to you is a link to your own GitHub profile, plus whatever you have deliberately turned on.
2.3 Why we are allowed to hold it
Your consent - Article 6(1)(a) of the GDPR - and nothing else. You made an account, you chose to be findable, and you ticked a box whose wording we recorded. Withdraw any part of that and the permission ends at the same moment the display does. Legitimate interests is not a basis on which we display anything about anybody.
Three decisions worth stating here, because they cost us something:
- No consent, no product. The three conditions at the start of this section mean we display nobody until they sign up and agree. We knew when we chose it that it empties the search results, and chose it anyway.
- No email address reaches a recruiter unless you typed it. The clearest harm from a tool like this is a compiled list of ways to reach people who never asked to be reached. The email address on your GitHub account stays on your sign-in record and is never shown; the only email address a recruiter can see is one you entered yourself. Ticking the Email box is what lets a recruiter see it; it is not what makes us hold it. We hold the typed address from the moment you save it until you clear the box and save again, and unticking the box in between stops the showing without ending the holding. We do not export any contact detail, ever - an exported file is the one copy we could not reach again if you asked us to.
- Your contact links are hidden unless you allow them, and stored only once you do. Not "hidden until you object" - hidden by default, for everybody, and each link is its own separate decision. We keep a copy of the links you ticked, so that showing your card does not need a request to GitHub for every link. What each box does to that copy is under What we hold about you; when a refresh happens is in the next section.
Consent is the basis for showing you. It is not the basis for everything we do. Keeping the service running, secure and paid for - sign-in, fraud and abuse prevention, billing records, server logs - rests on the bases described under For everyone who signs in and applies to us as an operator rather than to your profile as a display.
We do not sell your data, share it with data brokers, or use it for advertising.
2.4 How long we keep it, and when our copy is refreshed
Plainly, including the part that is not reassuring:
- Going Hidden stops the showing and deletes nothing. That is deliberate rather than a gap. Hiding is meant to be something you can undo, so what you had allowed is still allowed and still here, waiting for you, and nobody sees any of it while you are hidden. If you want something gone rather than dark, untick its box, untick the authorization box, or delete your data.
- Unticking the authorization box empties what we hold, in the same moment. The same happens when we publish a new version of the authorization wording: a receipt for the old wording stops counting, so until you tick the new one you are treated as if you had unticked. Your profile fields - name, picture, bio, location, the counts - are blanked in our copy and in every recruiter's search-history record of you; every contact link you had switched on is deleted; the stored search results that named you are dropped. What stays is your GitHub account id and username, the dated record of the consent and of the withdrawal, the language and skill figures worked out from your public repositories, your tick boxes as you left them, and the email address you typed, which stays in the box for you until you clear it. Delete your data and those go too - that is the next section.
- Our copy is re-read from GitHub - a refresh - at these moments and at no other: when you open your Account or Explore page here and the copy is more than six hours old; when a recruiter searches your username and it is more than an hour old; when a recruiter presses refresh on your card; and when a recruiter opens a collection you are saved in and the copy is more than fourteen days old; and whenever you act yourself - pressing Refresh from GitHub on your account page, or changing any box, which re-reads your profile under your new choice. What GitHub shows at that moment is what a recruiter sees until the refresh after it. This is the honest limit of our copy: something you changed on GitHub a minute ago may still be showing here. Unticking a box on your account page acts at once, and the re-read follows it.
- Nothing happens on its own. Each of these moments is an action by a person, and the ages are conditions checked at that moment, not clocks that fire. A copy that turns fourteen days old is not refreshed on day fourteen; it is refreshed the next time a recruiter opens a collection it is in and finds it older than that, which may be never. A profile nobody touches is never re-read and never deleted. A copy written while your consent stood is not deleted on age alone, and we are not going to describe a cleanup process we do not run. The ages above are freshness rules, not a retention policy.
That last gap is exactly why the next section exists. Withdrawing empties our copy of your profile and stops us writing you down again; deleting removes what withdrawing leaves behind - the record itself rather than an emptied row with your username on it, the analyses, and the address you typed. If you want it gone rather than hidden, the button is on your account page, and it does not wait for a search that might never come.
2.5 Your rights, and how to use them
Under the GDPR - and we apply the same process to everyone, wherever you are - you can:
- Stop, at any time, without giving a reason (Article 7(3)). Because our basis is your consent, withdrawing it is not a request we weigh: untick the authorization box, and the display ends and our copy is emptied in the same moment. Setting yourself Hidden ends the display too and deliberately deletes nothing, so you can come back to what you had - the section above says which does which. Withdrawing is as easy as giving it - the same page, the same click - and nothing about your account gets harder to use afterwards.
- Ask what we hold about you (access). Everything we could hold is listed above; write to us and we confirm which of it exists for you. If you never signed up, the answer is nothing, and we say so in writing after running the check rather than assuming it.
- Delete it (erasure, Article 17). The button on your account page, described next.
- Correct it. In practice, correct it at GitHub: we mirror your profile, so a change there is the change that lasts. Then press Refresh from GitHub on your account page and our copy follows at once, rather than at the next refresh. The address you typed and your address for notices you correct on the account page itself.
- Take it with you (portability, Article 20). Everything we hold about you on your consent is listed above and comes from GitHub, where it already is in a form you can export; write to us and we send you what we hold, as a file, in a common format.
- Restrict or object (Articles 18 and 21). While a question about your data is open, ask us to hold it without showing it: setting yourself Hidden does exactly that, at once, and we honour a written request the same way. For the processing we run on legitimate interests (3.2) you may object, and we stop unless we can show a ground that overrides yours.
- Not be judged by a machine (Article 22). Thleo makes no decision about you, automated or otherwise. The language proportions, the profile-confidence score and the proficiency figures are arithmetic over your public repositories, shown to a recruiter as context; whether anybody contacts you, interviews you or hires you is a decision a person makes elsewhere, and the Recruiter Terms of Service forbid using our figures as the basis for it.
How deletion works. Account → Delete my data → Delete all my data, then Delete everything in the dialog. It runs ten seconds after you confirm, with a Cancel beside it for those ten seconds: no request to file, no approval to wait for, no reason required. You have to be signed in with the GitHub account in question, and that is the whole of our identity check. An email saying "I am this username, delete them" can come from anybody, and acting on it would let anyone impersonating you erase a profile you chose to keep, or flood us with deletions of people who never asked - so we do not act on one, and we cannot delete on behalf of somebody who can no longer sign in to the GitHub account in question. If you have no Thleo account, there is nothing to delete. If you believe an old copy of you survived somewhere regardless, sign in with that GitHub account - a new account starts Hidden and shows nobody anything - and press the button, which also puts your account id on the suppression list below.
What "delete it" actually does. Everything we copied about you goes: the cached profile, every contact link you had switched on, the language and skill analyses, the record of your username changes, every recruiter's search-history entries for you, their notes and outreach log about you, the tags they applied and your place in their lists, the profile embedded in every saved repository you contributed to, the record of which terms you accepted, the notices we sent you and your newsletter subscription, and your developer account itself - including the email address you typed, if you typed one. Each of those is checked afterwards rather than assumed, so the page can tell you it happened rather than tell you it should have.
And it stays deleted. An erasure that the next search undoes is not an erasure, so deleting also puts your GitHub account id on a suppression list, and our database refuses to store you again - not because each part of the product remembers to check, but because the check sits underneath all of them. On that list we keep two things: the account id and the date. No username, no name, no email. It exists for one purpose: to recognise you and refuse. Only you can take an id off it, by signing in with that GitHub account again and ticking the authorization box; nothing a recruiter does, and nothing we do on our own, ever does. Three other records survive a deletion, and the Developer Terms of Service list them: a record that the deletion ran, the reason and the reply address you gave if you chose to give them, and your consent receipts, marked withdrawn, which prove the earlier display was consented to. If the same login is also a recruiter account, that account stays too.
Three things worth knowing before you press it:
- What recruiters wrote about you goes too. Their notes and outreach log about you, the tags they applied, your place in their lists and their search history of you are deleted, not blanked. That is a deliberate deletion of a customer's work, and the Recruiter Terms of Service tell recruiters it happens.
- A file a recruiter already downloaded is out of our reach. Those Terms require them to act on a removal request, but we cannot recall a file from someone's computer.
- A recruiter can still look you up on GitHub. The suppression stops us storing you; it does not stop a person opening your public GitHub page, which is not ours to prevent. What changes is that nothing they do puts your profile back into our database.
You also have the right to complain to a data protection authority - see Who we are, and how to complain.
How you were told. We read your profile from GitHub into our copy only about a person who is signed in and has ticked a box, so this policy and the authorization wording, both of which you can read before agreeing, are the notice. They stay public, with every past version, alongside the removal page.
3. For everyone who signs in
This applies to recruiters and developers alike: both sign in the same way, with GitHub, and both agree to the Terms for their side and to this policy by continuing past the sign-up page, beneath the sentence that says so. We record which version of each you agreed to and when. Here is exactly what permissions we request, what we store, and why.
3.1 GitHub permissions we request
When you sign in with GitHub, we request the following OAuth scopes:
| Scope | What GitHub says it allows | Why we request it |
|---|---|---|
read:user | Read your profile data | To know who signed in: your username, numeric id, name and avatar. Also, on a recruiter's own Account page, to read that recruiter's own public profile back to them - bio, company, location, the follower, following and repository counts, and the website and social links published on GitHub - live, each time the page opens, and stored nowhere. And, when a recruiter opens the import from their GitHub stars, the list of repositories they have starred, which 3.2 says is kept |
user:email | Read your email addresses | Your sign-in address. It is where the one-time codes that authorize a charge go, where term-change notices go unless you choose another address, and how a team invitation finds you |
public_repo | Read and write access to public repositories | To enable the "Star on GitHub" feature, which stars a repository on your own account when you click the button, and does nothing else |
GitHub's limitation: OAuth Apps cannot request star-only permission - GitHub bundles starring with repository write access. This is a limitation of GitHub's OAuth system, not our choice. Learn more in GitHub's OAuth scopes documentation.
3.2 What we store to run your account
Your sign-in record, for every account holder: the email address on your GitHub account, your name, your avatar URL, your GitHub username and numeric id, the date we last confirmed that username and avatar against GitHub (at sign-in, and when a recruiter presses Refresh GitHub profile on their Account page), and the access token from your GitHub sign-in, which is what lets the product read GitHub as you. The token is deleted when your account is deleted and cannot be revoked by us; Your control says how you revoke it. Also: which role you hold, which version of the Terms and of this policy you accepted and when, the address for notices if you set one, your newsletter decision (the exact wording you agreed to, the date, and, if you unsubscribed, the date and the reason if you gave one), and each term-change notice we sent you - document, version, date, and the email provider's message id. Your sessions - device and last activity - are held by our sign-in provider (WorkOS) and listed on the Sessions tab of your Account page, where you can revoke any of them.
Recruiters, additionally: the data you create in the product - collections, saved candidates and repositories, notes and their revision history, the outreach log, tags, search history, filter presets and pipeline stages, and the repositories you star inside Thleo. If you open the import from your GitHub stars, the list of repositories you have starred on GitHub as it stood when we read it, together with which of them you imported or dismissed, so that inbox keeps its place between visits. A collection, tag, note or filter preset you delete stays for thirty days in your recycle bin, from which you can restore it; 3.8 says when it is purged. Also your subscription status and billing customer id, and billing operation records. For every seat or billing-interval change, that record includes the IP address and the browser you used to request it and to confirm the code, kept as evidence that the charge was authorized (Recruiter Terms §5). Never card numbers: those never touch our servers. Stripe handles every operation that moves money; Service providers says what it and the others receive.
Developers, additionally: everything under For developers.
Why we may hold it. Data-protection law asks us to name, for each use, which of its permitted grounds we rely on. The sign-in record, your workspaces and your subscription are held because they are what the agreement you accepted needs to run - Article 6(1)(b), performance of a contract. Invoices and the billing operation records are kept because tax and accounting law require it - Article 6(1)(c), a legal obligation. Rate limits, abuse and fraud prevention, the hosting provider's request logs and the sign-in protections are our legitimate interest in keeping the service running and secure - Article 6(1)(f), and 2.5 says how to object. The newsletter is consent - Article 6(1)(a), and so is a developer's profile (2.3).
3.3 Where we reach you, and a newsletter only if you ask
On your Account page (the Preferences tab for recruiters, the Account page for developers) there is a box, Address for notices. It is where we write to you, and we write for exactly one reason without asking: to tell you that the Terms for your side or this policy have a new version (Changes to this policy). It starts as your sign-in address; change it if you would rather be reached somewhere else. It has no checkbox, because a person cannot opt out of being told the agreement they hold has changed - only choose where. The codes that authorize a charge do not go there; they go to your sign-in address, because they move money.
Below it is one box, and it starts unticked: the newsletter. Occasional mail about new features and how the product is doing, never more than a few times a month. Ticking it is your consent to that and to nothing else; the exact sentence beside the box is what we record, with the date. Every issue carries a one-click unsubscribe link that works without signing in, and unticking the box does the same. Unsubscribing happens first; after it, you may tell us why, and if you do we keep what you wrote so we can read it. Nothing about your account changes either way, and the box is never on the signup page.
3.4 What we never do
Despite having write access to public repositories, we strictly limit our usage:
- We NEVER write code to your repositories
- We NEVER create, modify, or delete issues or pull requests
- We NEVER change repository settings, webhooks, or collaborators
- We NEVER access your private repositories
- We NEVER share your data with third parties beyond the processors listed below
- We NEVER sell your data, and we run no advertising and no tracking
- We NEVER email you anything you did not ask for, beyond a notice when the documents you agreed to have a new version
3.5 Team workspaces
If you join a team, everything you create inside that team's workspace - collections, saved candidates and repositories, notes, tags, filter templates, linkages and the rest - is shared with every active member of that team. Data in your personal workspace stays private to you - teammates can never see it, and there is no way to move or share anything from a personal workspace into a team workspace, or back.
Teams also keep an append-only activity record of governance actions (members joining or being removed, seat changes, deletions of shared collections). It is readable by the team's admins only. An entry is written by the system at the moment the action happens and is never edited afterwards, by anyone: there is no screen for it, the database refuses updates and deletions from the application, and Thleo - the people who run it and the software itself - does not alter entries by hand or by any other means.
3.6 Your control
Revoke access anytime. Go to GitHub Settings → Applications, find "Thleo" in Authorized OAuth Apps, and click Revoke.
What happens after revoking: Thleo loses the GitHub access it needs to operate, so candidate search, profile data, and starring stop working, and the app will ask you to reconnect the next time you use it. Your saved data (collections, notes, teams) is untouched.
Recruiters: revoking does not cancel a paid subscription. Billing continues until you cancel it yourself in Account → Subscription → Open billing portal. If you are leaving Thleo for good, cancel first, then revoke.
Revoked by accident? Sign in with GitHub again and approve the permissions. Your collections, teams, and subscription will be exactly as you left them.
Delete your account. Developers delete everything themselves, with the button described under Your rights; it runs ten seconds after they confirm, and a developer has no subscription to cancel first. Recruiters have a button too, on the Danger Zone tab, with a thirty-day window: pressing it closes the account at once - signed out everywhere, out of every team, the workspace unreachable - and a daily job deletes it thirty days later; signing in again before then restores everything except the team memberships. The button refuses while a subscription is running, so that nothing is billed after the account is gone. What the deletion reaches, what stays with a team, and what survives are listed in the Recruiter Terms of Service, 12.1: in short, the personal workspace, the settings, the recruiter role and the sign-in record go; the billing operation records and their Stripe invoices stay, as evidence of charges you authorized, along with Stripe's own records on Stripe's retention, the collections, notes, tags and pipeline stages you created in a team workspace, which belong to the company that pays for the team, and a record that the deletion ran, carrying your account ids and the counts and nothing else. Neither button takes a request by email: an email cannot be verified the way a sign-in can.
3.7 Who is the controller, and when we are a processor
Data-protection law names two roles. A controller decides why and how personal data is used and carries the duties; a processor handles it only on a controller's instructions.
- For everything under For developers - the copy of a profile, the ticked links, the figures we work out - and for every sign-in record, Thleo is the controller.
- For what a recruiter writes about a candidate - notes, tags, collection membership, pipeline stages, search history - the recruiter, or the company they act for, is the controller and Thleo is their processor: we hold it for them, on their instructions, for their hiring purpose and nothing else. The contract that role requires is section 16 of the Recruiter Terms of Service, accepted with the rest of those terms.
For a developer this changes one practical thing: a request about what a recruiter wrote about you reaches the recruiter, and the Recruiter Terms require them to act on it; a request about what we hold reaches us.
3.8 How long we keep account data
Nothing about a person is deleted on a clock: what follows are the events that end our holding, not dates, and where the law fixes a period, it is named. Two jobs do run on a clock, both acting on a recruiter's own choices rather than on anyone's profile: the daily deletion of a closed recruiter account once its thirty days have passed, and the nightly purge of a recruiter's recycle bin. Both are on the list below.
- Your sign-in record, workspaces and settings: until your account is deleted - a developer's ten seconds after the button, a recruiter's thirty days after it (Recruiter Terms 12.1), during which the closed account is held untouched so that it can be restored.
- Your recycle bin: a collection, tag, note or filter preset you delete is held for thirty days so that you can restore it. A job runs nightly at 03:00 UTC and deletes, for good, everything whose thirty days have passed - so on the first night after day thirty, never the same day. Restoring it is the one thing that stops that.
- The record that a recruiter's deletion ran: kept with the billing operation records, for the same period, because it is the other half of the same evidence.
- Billing operation records and invoices: for as long as tax and accounting law in [[JURISDICTION]] requires after the last charge, and no shorter, because they are the evidence that a charge was authorized.
- Term-change notices: the record that a notice was sent stays as long as the account it was sent to, because it is what shows you were told.
- Newsletter subscription, and the reason you gave when you unsubscribed: until your account is closed, or until you subscribe again, which replaces it.
- The record that a deletion ran, and a deleted developer's account id on the suppression list: until that person signs in again and re-authorizes, which is the one event that lifts it; nothing else does.
- Hosting request logs: one day, which is what Vercel keeps on the plan we run on, and we do not export them anywhere.
- Rate-limit counters and the daily searched-usernames tally: short-lived by construction; each expires on its own within a day.
4. Cookies
Every cookie the product sets is needed to run it, so there is no banner to click and nothing to consent to. They are:
| Cookie | Set by | What it does | How long |
|---|---|---|---|
wos-session | our sign-in provider | keeps you signed in | until you sign out or the session expires |
thleo-active-app-mode | Thleo | remembers whether you last used the recruiter or the developer side | 30 days |
thleo-active-workspace | Thleo | remembers which workspace, personal or team, you were in | 30 days |
sidebar_state | Thleo | remembers whether you left the sidebar open or collapsed | 7 days |
thleo-auth-callback-flow | Thleo | carries the role you chose across the GitHub sign-in round trip | the round trip only |
| the sign-in start cookies | Thleo | protect the sign-in round trip against forgery | the round trip only |
Your theme choice is kept in your own browser and never sent to us. There are no analytics, no advertising, no tracking cookies, and no third-party scripts on any page; the fonts are served from our own site. Avatar pictures are loaded from GitHub's own image servers, which is the one request a page here makes to somebody else's.
5. Data storage and security
- All data is stored in encrypted form on disk and travels only over HTTPS
- Row-level security isolates every workspace's data from every other, in the database itself rather than in each part of the application that remembers to check
- The access token from your GitHub sign-in is stored as a column in the database, on disks our database provider encrypts; the column is readable by the server only, never shown to anyone, and deleted with your account
- Money-moving operations are recorded with a traceable operation id, the wording you authorized, the price, the timestamp, and the IP address and browser at request and at confirmation, as described in Recruiter Terms §5
- Every request to the product passes through our hosting provider, which keeps request logs including IP addresses on its own retention; rate limits are counted per account, and per visitor IP address on the public developer page, in short-lived counters
6. Service providers we rely on
Each receives only what its job needs. This is the whole list, and the country column is where that provider's company sits, which is what decides the transfer rules further down.
| Provider | What it receives | What it does with it | Entity country |
|---|---|---|---|
| Stripe | Your sign-in email and name; for a team, the team's name and the email of the person who created it; every payment | Payment processing. Card details never touch our servers | United States |
| WorkOS | Your GitHub identity (email, name, avatar) and your sessions | Sign-in and sessions; sends team invitation emails; runs sign-in protections against sign-in attempts: bot detection, brute-force detection, impossible-travel detection (a sign-in from a place the last one could not have reached in the time) and repeat-sign-up detection | United States |
| Supabase | Everything described in this policy that is not named as held elsewhere | The database | Canada |
| Vercel | Request logs, including IP addresses | Hosting and running the application | United States |
| Upstash | Rate-limit counters keyed to your account id, and to the visitor's IP address on the public developer page; the daily tally of searched usernames | Short-lived counters | United States |
| Resend | The address and the content of each email we send | Delivers the one-time codes and receipts for billing changes, the term-change notices, and the newsletter | United States |
| Google (Google Workspace, contracted through Google Cloud Brasil Computação e Serviços de Dados Ltda.) | The messages you send to support@thleo.app, including requests about your data, and our replies | Hosts the support mailbox | Brazil |
Each is a processor acting on our instructions, bound to us by a data-processing agreement. GitHub is different: it is where the public developer data in the product comes from, not a processor of ours. We do not share your data with anyone else.
Where the data goes. Supabase hosts the database in Canada, a country the European Commission recognises as giving personal data adequate protection, so nothing further is needed for it. Every provider shown above as a United States company processes data there under its data-processing agreement with us, which carries the European Commission's Standard Contractual Clauses for the transfer, and where that provider is certified under the EU-US Data Privacy Framework the certification applies as well. Google is contracted through its Brazilian company because that is where Thleo is billed; the mailbox runs on Google's own infrastructure under Google's data-processing terms for Google Workspace.
When this list changes. A provider is added or removed by publishing a new version of this policy, so the version history beside it is the record of who has ever been on this list and when. Nothing is added quietly.
7. Who we are, and how to complain
Thleo is operated by [[ENTITY_NAME]], established in [[JURISDICTION]], which is the data controller for the processing described in this policy. The two brackets are filled by counsel before sign-ups open; nothing else in this policy depends on the choice.
For anything about your own data, write to support@thleo.app. If you are not satisfied with our response, you have the right to lodge a complaint with the data protection supervisory authority in your country of residence, or with the authority in [[JURISDICTION]]. You do not have to talk to us first.
8. Changes to this policy
Every version of this policy stays publicly readable on this page's version history, so you can see exactly what changed and when. Nothing is edited in place after it goes live: a change is a new dated version, and the old one stays up beside it.
We announce a new version to every account holder, recruiter or developer, at least 14 days before it takes effect: one email to the address for notices (your sign-in address unless you changed it) and a notice inside the product, where it can be accepted with one click. Continuing to use Thleo after that date is acceptance, and is recorded as such with the date of the notice. If you would rather not accept it, a developer can delete everything and a recruiter can close their account before it takes effect. Nothing in this paragraph applies to a developer's recruitment authorization, which is consent and must be ticked again by the person.
9. Questions
Email support@thleo.app. See also the Recruiter Terms of Service, the Developer Terms of Service, the removal page, the FAQ, and the glossary for the words these documents use in a fixed sense.