Remove my profile

If you never signed up for Thleo, we hold nothing about you. If you did, you can delete everything yourself, in one click, and this page says exactly what that reaches.

Why we have anything at all

Thleo is a search tool for tech recruiters, and it only holds developers who signed up and authorized it. A profile exists here when its owner has a Thleo account, has set themselves findable, and has authorized us to show their public GitHub information to recruiters. If a recruiter searches somebody who has not done all three, they are told there is no profile, and nothing is stored - not masked, not kept quietly and unread. Our database refuses to write the row.

So if a recruiter found your GitHub work and wrote to you, they found it on GitHub. That is not us being coy: there is no record of you here for them to have used.

We are not the owner of anything GitHub publishes about you. GitHub publishes it, you decide what is in it, and we do not read it at all unless you have told us to.

Exactly what we hold

If you never signed up, the answer for every line below is: none of it. This is the ceiling - the most that can exist about anybody here, and it exists only for a developer who has an account, is findable, and authorized us. It is published in full so you can check what we would be holding if you had, rather than take a shorter list on trust.

From your public GitHub profile

  • Your GitHub username, numeric account id, and the link to your GitHub profile
  • Your display name, bio, company, and location - whatever those fields say on GitHub
  • Your avatar image URL
  • Public counts: repositories, followers, following, and public contribution activity
  • The programming languages inferred from your public repositories
  • The public organizations GitHub shows on your profile
  • When your account was created, and when we last read your profile
  • Any earlier GitHub username of yours we saw change
  • A second copy of your name, bio, location, avatar, company and “available for hire” flag inside the search history of each recruiter who looked you up
  • If you signed up and ticked them: the website and social links you chose to show - and only those. Unticking one deletes our copy immediately; removing it from GitHub removes ours at the next refresh
  • Your username inside recruiters’ own records: their shortlists, their notes and outreach log about you, their search log, and inside any repository of yours they saved

What we never hold

  • Your email address, if you never signed up. If you did, the address on your GitHub account is on your sign-in record, to run your account and send you notices about new versions of our terms and privacy policy, and it is never shown to a recruiter. The only address a recruiter can ever see is one a developer typed in themselves
  • Your personal website, blog, or any link you list on your profile, if you never signed up - and any link you did not tick yourself, ever
  • Any social handle or account you have not switched on: X/Twitter, LinkedIn, Mastodon, Bluesky, or any other
  • Your phone number, physical address, or any other way of contacting you off GitHub
  • Anything at all from private repositories, private profile fields, or private activity

Nothing here is scraped, and we read nobody's email address from GitHub except the person signing in: yours goes on your sign-in record, to run your account and to tell you about new versions of our terms and privacy policy, and it is never shown to a recruiter. A website or a social link is stored only for a developer who signed up, authorized us, and ticked that particular link - and they can untick it, which deletes our copy in the same moment. The one contact detail that never comes from GitHub at all is an email address a developer with an account typed in themselves so recruiters could write to them; they can delete it in the same box they typed it into. If you never signed up, none of that can exist for you: there is no record of you for a link to attach to, we hold no way of contacting you, and we give a recruiter no route to you at all - not even a link. As far as this product is concerned you are not here.

How long we keep it

This applies to a developer who authorized us. For everybody else there is nothing to keep and nothing to refresh, so the question does not arise.

A cached profile is re-read from GitHub at these moments and no other: when you open your Account or Explore page and the copy is more than six hours old; when a recruiter searches your username and it is more than an hour old; when a recruiter presses refresh on your card; and when a recruiter opens a collection you are saved in and the copy is more than fourteen days old; and whenever you act yourself, by pressing Refresh from GitHub on your Account page or changing any box. What GitHub shows at that moment is what a recruiter sees until the next one. If GitHub reports the account gone at a refresh, the copy is deleted rather than kept.

Being straight about the limit: every refresh is started by somebody. There is no timer that deletes a profile nobody looks at. That is the gap the button on your Account page exists to cover - press it, and it is gone without waiting for a search.

How to delete it

This page is about developer data. Closing a recruiter account is a different button, because a recruiter is a paying customer: it is on the Danger Zone tab of the recruiter Account page, it refuses to run while a subscription is still renewing, and the account is deleted thirty days after it closes. The Recruiter Terms, 12.1 walk through it.

Sign in with GitHub, open your account page, and under Delete my data press Delete all my data, then Delete everything in the dialog that opens. A ten-second countdown runs with a Cancel beside it; when it ends, the deletion runs and cannot be undone. Nobody reads a request first, nobody weighs a reason, and you can say why or not.

It needs your GitHub sign-in, and that is the whole of our identity check. An email saying “I am this username, delete them” can come from anybody, and acting on it would let a stranger erase a profile you chose to keep - or flood us with deletions of people who never asked. Signing in through GitHub proves the account is yours in a way no email can.

If you have no Thleo account, there is nothing to delete: we hold nobody who has not signed up, and our database refuses to write such a row. If you believe an old copy of you survived somewhere regardless, sign in with that GitHub account - a new account starts Hidden and shows nobody anything - and press the button. That also puts your account id on the list below that stops you ever being fetched again.

It closes your Thleo account: the sign-in record holding your email address, name, avatar and the access token from your GitHub sign-in is deleted, and you are signed out. Nothing on GitHub is touched.

Unless the same login is also a recruiter account on Thleo. If it is, we delete all of your developer data exactly as described, and we do not close the account: your recruiter workspace and your sign-in stay, and you stay signed in. Deleting your developer data is not a request to close a service you are paying for. The sign-in record - your email address, your name, your avatar and the access token from your GitHub sign-in - stays too, because that is what the account runs on. If you want that gone as well, close the recruiter account; it asks you to cancel your subscription first. The deletion dialog tells you which of the two applies to your login before you confirm.

Anything the button cannot do

Email support@thleo.app to ask what we hold about you, or for anything else on this page. If you never signed up, the answer is nothing, and we say so in writing after running the check rather than assuming it.

It does not delete. An email cannot be verified the way a sign-in can, so we do not act on a deletion request made by email, and we cannot delete on behalf of somebody who can no longer sign in to the GitHub account in question - we could not tell that request from a stranger's. The button above is the only route. A person reads the mailbox; we have not set a guaranteed reply time and will not claim one we do not measure.

What happens next

  • We delete the cached copy of your profile, the language and skill analyses built from your public repositories, and the record of any username change we saw.
  • We delete you from every recruiter's records too: their search history entries about you, their shortlist memberships, their notes and outreach log about you, and your entries inside every saved repository that embedded you as a contributor.
  • We delete your developer account and the sign-in record behind it - the email address on your GitHub account, your name, your avatar and the access token from your GitHub sign-in - and sign you out. Signing in again would give you a fresh, empty one. The one exception: if that same login is also a recruiter account, we leave it alone. Your developer data still goes; the account you pay for is not what you asked us to delete.
  • We add your GitHub account id to a list that stops you being fetched again, so a recruiter searching your username next month does not put the profile back.
  • We check each of those afterwards rather than assuming, so the confirmation on screen is a count of what was removed and not a description of what should have been.
  • The page tells you it is done, and what, if anything, is still pending.

What survives, in full:

  • Your GitHub account id and the date, on the suppression list - see below. Two columns, kept until you yourself sign in and authorize again, so nothing a recruiter does ever fetches you again.
  • The record of the erasure itself: which tables were touched, how many rows, on what date. It exists so that if you ever write back saying “you never deleted me”, we can prove we did.
  • The reason you gave, and the address you gave for a reply, if you gave either. Both boxes are optional, and leaving them blank leaves nothing to keep. The address is used for that reply and nothing else.
  • Your consent receipts, marked withdrawn - which version of the wording you agreed to, when you agreed, and when it ended. Only exists if you had an account and ticked the box. It is what proves the earlier processing was consented to, and destroying it at the moment of erasure would destroy that proof.
  • And, only if the same login is also a recruiter account: that account. Its workspace, its collections and notes, and the sign-in record behind it - including your email address, your name, your avatar and the access token from your GitHub sign-in. Everything we held about you as a developer is gone; you still have a Thleo account, because you did not ask us to close one.

Nothing else survives. A recruiter who wrote a note about you loses that note, and their records keep only the parts that were never about you.

The one thing we keep in order to refuse you. To make sure no recruiter ever fetches you again, we have to remember something about you: your GitHub account id, a number. That list stores the number and the date, and nothing else - no username, no name, no email, no reason. The reason and reply address above, if you gave them, are kept with the record of the erasure, not on this list. It exists for one purpose, which is to recognise you and refuse. Only you can remove it, by signing in with that GitHub account again and ticking the authorization box; that is a later consent and it outranks the list. There is no way around the irony, so we would rather state it than bury it.

Deleting your GitHub account, or making it private

If you never signed up for Thleo, there is nothing here for it to reach and nothing you need to do - this is about a developer who authorized us and would rather leave through GitHub than through us.

For them it works. The next time a recruiter looks them up, GitHub reports the account missing, we confirm with GitHub that the account itself is gone rather than renamed, and our copy is deleted everywhere, their Thleo developer account included - the same outcome as the button, arriving on GitHub's schedule instead of ours. If nobody looks them up, it waits; the button on your Account page does not.