The agreement between you and Thleo about your GitHub profile, your developer account, and what you can make us stop doing.
These terms are for developers. If you use Thleo to search for candidates, the Recruiter Terms of Service cover that side, and they apply to you separately.
Table of contents
- Who these terms are for
- What Thleo is, and where your information comes from
- One rule, and nothing outside it
- Your developer account
- What you control
- Turning something off
- Deleting everything
- What we never do
- What we ask of you
- Ending this
- Changes to these terms
- What we do not promise
- Governing law, and how to reach us
1. Who these terms are for
You, if you make a developer account: these terms are the agreement between you and Thleo.
And you, in a different way, if you have a public GitHub account and never sign up. A contract cannot bind somebody who never agreed to it, and this one does not try. If you have no Thleo account, we hold nothing about you and show nothing about you. That is §3, it is the shortest section here for a reason, and it is a promise made to you in public rather than a clause you accepted: this document names you so that you can check it and hold us to it.
If you make a developer account, you accept these terms by continuing from the Developer card when you sign up, beneath the sentence that says you agree to them, and we record which version you accepted and when. By continuing you also confirm that you are at least 16 years old; a profile here rests on your consent, and the law in much of Europe lets nobody younger give that consent alone. That is a separate act from the authorization box on your Account page (5.2): accepting these terms is what having an account requires, while the authorization is the consent to be shown to recruiters, and you never have to give it. Sections 5, 6 and 7 need an account, because signing in with your GitHub account is the only way we can tell it is really you giving the instruction; 7.1 says why that matters most for deletion.
2. What Thleo is, and where your information comes from
Thleo is a paid platform that helps tech recruiters find candidates for their open positions, using GitHub as the source. Recruiters use it to look up developers by GitHub username, save them to collections, write their own notes, and read a breakdown of the languages in their public repositories.
Everything about you that Thleo takes from GitHub comes through GitHub's official API. One
host, api.github.com, and two documented endpoints on it: the GraphQL API at
https://api.github.com/graphql for everything, and the REST endpoint
https://api.github.com/users/<your-username>/orgs for the one thing GraphQL will not answer
without a permission we refuse to ask for, which is the list of organizations you have made public.
We do not crawl github.com, we do not read HTML pages, we do not buy data, and we do not merge in
anything from another site. There is no scraping code in this product to switch on.
None of this reaches a recruiter unless §3 is satisfied for you. The list below is what a recruiter can see about a developer who has an account, is findable, and has authorized it - not a list of what we hold about the world. Three different kinds of thing end up in front of a recruiter, and they are worth separating:
- Copied from your public GitHub profile. Username, numeric account id, profile link, name,
bio, location, company, avatar, "available for hire", your public counts (repositories, gists,
followers, following), your public organizations, your public contribution activity, when the
account was created and when it was last publicly active. Whether your
username/usernamerepository has a README - only whether: the README itself is read from GitHub each time a recruiter opens it, and never stored. - Worked out from your public repositories. Which languages you write and in what proportion, a "profile confidence" score describing how complete and readable your public work is, and per-skill proficiency percentages. These are our arithmetic about your public code, not statements from you.
- Counted by us, about activity here. How many times your username has been searched and by how many different recruiters, how many times you appear in recruiters' collections and how many different workspaces hold you in one (counts only, never which recruiters or workspaces), when our copy of you was last read from GitHub, and a daily tally of searched usernames that ranks the most-searched profiles. GitHub does not publish this; we create it. It measures what recruiters did on Thleo. It says nothing about you, and it is not a judgement of your work. There is no switch for these counters today, and if you ask us to delete your data they go with everything else.
- Your earlier usernames. If you change your username on GitHub after we have seen you, we keep a dated record of the change. A recruiter who had already saved or searched you under your old username still finds you under the new one, so a rename does not lose you from their list. Anybody else who searches your old username is told there is no profile, exactly as GitHub tells them: a rename is not undone here for people who did not already know you.
We never see anything GitHub keeps private, with one exception we ask for by name: the email address on your GitHub account, which the sign-in reads so that we can run your account and reach you about these documents (5.6). It goes on your sign-in record and nowhere else; no recruiter ever sees it. Private repositories, other private profile fields and private activity are not returned to us and we could not show them if we wanted to.
When our copy of you is refreshed. We keep a copy of what we read, so that a recruiter's page does not need a request to GitHub every time it loads. That copy is re-read from GitHub - a refresh - at these moments and at no other: when you open your Account or Explore page here and the copy is more than six hours old; when a recruiter searches your username and it is more than an hour old; when a recruiter presses refresh on your card; when a recruiter opens a collection you are saved in and the copy is more than fourteen days old; and whenever you act yourself - pressing Refresh from GitHub on your Account page, or changing any box in §5, which re-reads your profile under your new choices. There is no timer: nothing refreshes a profile nobody is looking at. Wherever this document says "at the next refresh", this is what it means. Every box in §5 acts immediately, and the re-read follows it rather than the other way round.
3. One rule, and nothing outside it
Nothing about you is shown here, counted here, or newly stored here unless all three of these are true at the same time. You control all three, and any one of them failing is enough.
- You have a Thleo developer account, made by you, signed in with your own GitHub account.
- You have set yourself findable - Visible to recruiters or Public in 5.1. A new account starts Hidden.
- You have ticked the authorization box in 5.2 and saved it, on the wording that is current today. A receipt for wording we have since replaced does not count; see §11.
Miss any one of them and a recruiter who searches your username is told there is no profile here - word for word the answer they get for a username GitHub never heard of, with no hint that anyone made a choice. That is what somebody with no account gets, what a Hidden account gets, and what an account whose authorization has been withdrawn or superseded gets. Not a thinner profile, not a name with the details missing: nothing.
Nothing new is stored either, which is the part that is easy to promise and hard to build. Our database refuses to write a copy of anyone who does not satisfy all three, underneath the whole product rather than in each part of it that remembers to check, so nothing is ever collected about somebody who did not agree. What happens to a copy made while all three held depends on which one stopped: going Hidden keeps it, shown to nobody, so you can come back to it; withdrawing empties it. §6 says exactly what each does. You are not counted either: how many recruiters searched you, how many saved you, how often you were read - none of that accrues to a person the rule does not cover.
Your legal basis for all of it is your consent - Article 6(1)(a) of the GDPR - and only your consent. Withdrawing it in 5.2 ends the permission, and the display, at the same moment.
No link you publish on GitHub is shown even when all three hold. Every website and social-media address on your GitHub profile is off until you tick it, one at a time, in 5.4.
4. Your developer account
- It is free. There is no subscription, no trial, and no payment step on the developer side.
- You sign in with GitHub. We never ask you for a password and never see one. Sign-in runs through WorkOS, which handles the GitHub OAuth round trip for us.
- One account, your own GitHub identity. The account is bound to the GitHub account you signed in with. It is not for signing in on somebody else's behalf.
- The same person can hold both sides. If you also use Thleo as a recruiter, that is a separate area of the app with its own subscription, and the Recruiter Terms of Service govern it. A recruiter cannot see any of your developer settings, and nothing here tells anyone what you chose.
- We may change what the developer area does. It is a young part of the product; pages may be added, changed or removed. What will not change without a new version of this document is what we are allowed to show and what you can make us stop showing.
5. What you control
Everything in this section lives on one page: Account, in the developer sidebar. Every control takes effect when it is saved, and every one of them is reversible.
A ticked box means shown. An unticked box means hidden. That is true of every box on the page.
5.1 Who can find you
One switch, three settings. This switch is one of the three conditions in §3, not a substitute for them - setting yourself visible without the box in 5.2 ticked shows nobody anything.
- Hidden - nobody can find your profile here. A recruiter searching your username gets the same answer as for a username that was never on GitHub, with no hint that you chose this. You also drop out of the collections of any recruiter who had already saved you, for as long as you stay hidden.
- Visible to recruiters - only recruiters signed in to Thleo.
- Public - recruiters, and anyone on the internet who opens your public Thleo page.
The two findable settings differ in one thing: whether you have a public page. Visible to
recruiters puts you in front of signed-in recruiters only, ever. Public does the same and also
serves a page at thleo.app/developers/your-username that anyone with the link can open without
signing in. That page shows exactly what a recruiter sees - the same boxes in 5.3 to 5.5 govern
it - and nothing more. It never re-reads GitHub, so a visitor cannot spend your GitHub quota; it is
reachable only by your exact username, listed nowhere on Thleo, and marked not to be indexed by
search engines. Somebody opening it for a username that is Hidden, Visible to recruiters, or not
on Thleo at all gets the same not-found page, word for word.
Three things this switch does not reach. It does not, on its own, make you findable: the authorization box in 5.2 is a separate act and §3 needs both. It changes nothing on GitHub: your GitHub profile stays exactly as public as GitHub makes it, and anyone, recruiters included, can still open it there - this switch only covers what Thleo shows. And if a recruiter saved a repository you contribute to, the copy of your details inside it follows the tick boxes in 5.3, not this switch.
5.2 The authorization box
Under the switch, once you are findable, there is one checkbox with the authorization wording on it.
Checking it and saving stores a receipt: which version of that wording you agreed to, when you agreed, that you were signed in through GitHub at the time, and - later, if you change your mind - when you withdrew. Unchecking the box stamps the withdrawal date on the same receipt.
We never delete a receipt. A withdrawn one is the only thing that shows the period before the withdrawal was consented to. It survives even a full deletion of your data; see §7.
Two plain facts about what the box does:
- It is the consent everything else rests on. With it unchecked - or checked only against wording we have since replaced - you are not shown, you are not counted, and nothing new about you is written down, whatever the switch in 5.1 says. That is condition 3 of §3, and it is checked on every read rather than trusted to the page you are reading it on. If you had checked it and then unchecked it, what we already held is emptied at the same moment; §6 says exactly what that reaches and what it leaves.
- Checking it is also what unlocks the field controls in 5.3 to 5.5. While it is unchecked, those controls are locked, and unchecking it locks them again.
The Delete my data button in §7 is never locked by any of this. Erasure is a stronger right than consent, and it is not going to sit behind giving one.
5.3 The profile fields, one box each
Five boxes, each governing one thing on a recruiter's screen:
| Box | What it governs |
|---|---|
| Profile picture | Your avatar. With it off, recruiters see your initials instead. |
| Bio | The line about you that recruiters read first. |
| Company | A small pill beside your location. |
| Location | A small pill near the top of your card. |
| Readme | A button that opens your GitHub profile README. Only appears if you have one. |
These five arrive already ticked on a new account. That is deliberate and it is not a consent we manufactured: until §3 is satisfied - an account that is Hidden, or findable with the box in 5.2 unticked - they show nobody anything, and they exist so that choosing to be findable and authorizing it shows the profile GitHub already publishes rather than a blank page you then have to fill in. Untick any of them and we stop showing that field. Nothing puts one back but you - signing in again does not, and neither does anything else.
We keep a copy of these values so we can show them without asking GitHub every time. Change or clear any of them on GitHub and our copy follows at the next refresh (§2 says when that is). Untick the box instead and we delete our copy straight away, whatever GitHub still says.
Five things have no box, and we would rather name them than let you look for the switch. Your username, your name, your profile link, your follower and following counts, and the "available for hire" flag you set on GitHub. The counts are arithmetic GitHub performs about a public account; the rest is how a recruiter identifies which public account they are looking at. Deleting your data removes them along with everything else.
5.4 Your links, one box each
Every link you publish on GitHub - your website, X, LinkedIn, Mastodon, Bluesky, GitLab, Stack Overflow and the rest - is off for everybody, account or no account. If you want a recruiter to be able to reach you directly, ticking one of these is the only thing that makes it happen.
Each link is its own decision. GitHub names about fourteen providers and leaves the rest unlabelled; a personal blog, a niche forum, a second Mastodon server, a link tree. Rather than one "other links" box that would reveal all of them at once, each unnamed link gets its own row and its own box. Wanting a recruiter to read your blog is not the same as wanting them to find your Reddit account, and a control that cannot say so is collecting agreement to a question nobody asked.
We store the links you tick, and only those. A link with its box unticked is never written down anywhere. There are two ways one goes away, and they are not equally fast:
- Untick the box here and we delete our copy in the same moment - not hide it, not mark it withheld. There is no state in which a link you withdrew is still stored.
- Remove the link from GitHub and our copy goes at the next refresh (§2 says when that is). Until then a recruiter can still see it here. If you want it gone now rather than then, untick the box.
Your decision about an unnamed link is filed under a fingerprint of the address - a one-way code computed from it - rather than under the address itself. Both the fingerprint and the address exist only while the box is ticked; unticking deletes both, as above. One consequence, while it is ticked: removing a link from GitHub is not read as unticking it. The fingerprint keeps your decision, so if you publish the same address again later it comes back already ticked. Untick the box if that is not what you want.
Unticking a link here hides it on Thleo and nowhere else. The links on your GitHub profile are published by you, on GitHub, under GitHub's rules, and stay public there to anyone who opens your profile - recruiters included. What a box here decides is only whether Thleo shows the link as well.
5.5 An email address, only if you type one
There is one text box on that page that a recruiter can ever see, and it holds the only thing a recruiter is shown that you typed rather than published on GitHub. The page has other boxes that no recruiter sees: the address for notices and the newsletter tick (5.6) and, in the deletion dialog, an optional reason and a reply address (§7). If we ever add another box a recruiter can see, it will be named here, in a new version of these terms.
- It is optional and it starts empty. GitHub publishes no such field for us to read, we never ask GitHub for one, and we never copy the address you signed in with.
- It is off by default like every other contact row. Typing an address does not show it; the Email box has to be ticked as well.
- A recruiter sees the address itself, in text, and can write to you. Not an icon - the address. That is the whole point of the field, and it is the one row here whose consequence is a stranger arriving in your inbox.
- Clearing the box and saving deletes it. We stop holding it at all. Your Thleo developer account is untouched, and nothing changes on GitHub.
- We do not send anything to it. See §8.
- A recruiter who has seen it can keep it. That is what a contact detail is: once it is on somebody's screen it can be copied into their notes or their hiring system, and nothing you do here reaches that copy. Unticking the Email box stops us showing the address from then on; clearing the box and saving deletes our copy of it. Neither undoes a copy somebody already took, and we will not pretend otherwise. What we can do is bind the person who took it: our Recruiter Terms of Service require a recruiter to use contact details only for the role they approached you about, to act on a request from you to stop contacting them or to delete what they hold, to keep those details inside that hiring team, and to delete them when the role is over.
- No export carries it. See §8.
Like everything else here it rests on your consent (§3) - and this one field is the only thing in the product you gave us rather than published on GitHub, so removing it deletes the value rather than hiding it. Unticking the box is the other, weaker act: it ends the showing and leaves the address in the box for you.
5.6 Where we reach you, and a newsletter only if you ask
Under the same page there is a second address box, and it is nothing to do with recruiters. It is where we write to you, and we write for exactly one reason without asking: to tell you that these terms or the privacy policy have a new version (§11). It starts as the address on your GitHub account, because that is the one address every account has; change it if you would rather be reached somewhere else. It has no checkbox, because a person cannot opt out of being told the agreement they hold has changed - only choose where.
Below it is one box, and it starts unticked: the newsletter. Occasional mail about new features and how the product is doing, never more than a few times a month. Ticking it is your consent to that and to nothing else; the exact sentence beside the box is what we record, with the date. Every issue carries a one-click unsubscribe link that works without signing in, and unticking the box does the same. Nothing about your account changes either way, and the box is never on the signup page: agreeing to these terms and agreeing to be written to are two different things.
6. Turning something off
Unticking a box takes effect immediately. We do not keep a "hidden" flag; we delete the row that allowed the field, and - for a link - the stored value itself, in the same write. There is no state in which a withheld GitHub value is still stored as withheld.
The address in 5.5 is the exception, because it is the one value you typed rather than published. Unticking Email stops us showing it and leaves it in the box for you; clearing the box and saving is what deletes it. We are not going to throw away something you typed because you unticked a box next to it - but that means the two acts are different, and only the second one ends our holding it.
Going Hidden is different, and deliberately so. It stops recruiters seeing anything, and it unticks nothing: what you had allowed is still allowed and still stored, waiting for you. We do drop the stored search results that already named you, so nothing serves an old copy of you while you are away. If you want something gone rather than hidden, untick its box, untick the authorization box, or delete your data.
Unticking the authorization box in 5.2 turns off all of it at once - you stop being shown, you stop being counted, and the permission we were holding your profile under is gone. It runs every update in the list below over every field at once, and goes one step further: the profile fields in our copy are emptied, and emptied in every recruiter's search-history record of you, rather than only the fields you had specifically unticked. Emptied rather than deleted: the records stay, with your username and nothing else in them, so that ticking the box again brings you back rather than starting you over. Deleting the records themselves is §7.
Going Hidden in 5.1 does none of that. Of the list below it does one thing - the stored search results are dropped - and nothing else: no field is unticked, no value is deleted, no copy is emptied. The two controls sit next to each other on the same page, so it is worth saying twice: Hidden is the reversible one.
We then update every copy that already exists:
- the cached profile is re-read from GitHub and rewritten under your new choices - except after unticking the authorization box, where there is nothing left we would be allowed to write, so we empty it instead and read nothing;
- the stored search results for your username are dropped;
- the unticked fields are cleared from every recruiter's search-history record of you, in one pass, not just the recruiter who searched you most recently;
- your entry inside the stored description of any repository a recruiter saved is rewritten with the unticked fields removed. Nobody is shown the people inside those descriptions in any case; this keeps what is stored honest, not only what is seen.
What unticking the authorization box leaves. Your account, and your tick boxes exactly as you set them, so checking the box again returns you to the settings you left rather than a blank page. The dated record of the consent and of the withdrawal - see 5.2. The language, profile-confidence and skill figures worked out from your public repositories. And the address in 5.5, if you typed one: it is yours, and we are not going to throw it away because you unticked something else. If you want those gone as well, that is §7.
Four limits, stated because they are real:
- Turning a field back on is not retroactive inside a saved repository's description. Unticking overwrites the value stored there, and there is nothing left to restore it from; it reappears only when a recruiter saves the repository again. Only your picture, bio, company and location exist there to be removed; your username, name and profile link stay, as in 5.3.
- An update can fail - GitHub can be unreachable, a write can be refused. Your choice is recorded either way, and the Account page tells you when an update is still pending. Until it lands, an older copy can persist.
- A recruiter who already exported a file has that file. A download is outside our reach. Our Terms of Service require recruiters to secure exports and to act on a withdrawal we pass on, but we cannot recall a file from someone's laptop and will not pretend otherwise.
- A recruiter's own notes are their writing. Hiding a field does not change what somebody wrote about you in their own workspace. Deleting your data does - see §7.
7. Deleting everything
You can delete everything Thleo holds about you, completely, whenever you want. It runs ten seconds after you confirm, and you can stop it in those ten seconds: no request to file, no approval to wait for, no reason required. If you do tell us why, a person reads it, and if you leave an address for a reply, you get one.
7.1 How, and why it needs your sign-in
Account → Delete my data → Delete all my data. You type a word to confirm you have read what goes; then a ten-second countdown runs with a Cancel beside it, and when it ends the deletion runs. Nothing can undo it afterwards. You can say why if you want to; the question is optional and skipping it changes nothing.
You have to be signed in with the GitHub account in question, and that is the whole of our identity check. An email saying "I am this username, delete them" can come from anybody, and acting on it would let a stranger erase a profile you chose to keep - or flood us with deletions of people who never asked. Signing in through GitHub proves the account is yours in a way no email can. If you have no Thleo account, §3 means we hold nothing about you, so there is nothing to delete. If you believe an old copy of you survived somewhere regardless, sign in with that GitHub account - a new account starts Hidden and shows nobody anything - and press Delete all my data, then Delete everything in the dialog that opens. That also puts your account id on the suppression list in 7.4, so nothing a recruiter does can bring you back.
7.2 What goes
The cached profile. Every contact link you had switched on, counted and checked rather than swept away with the profile row it hangs off. The language breakdown and the profile-confidence and skill figures worked out from your public repositories. The record of your username changes. The queue entries for fetching you. Every recruiter's search-history record of you - whole records this time, not emptied ones. Every search log entry naming you. Your membership of every recruiter's collection. The notes recruiters wrote about you, and their outreach log of when they were in contact with you - that is a deliberate deletion of somebody else's writing, not an accident. Every tag anyone applied to you. Your developer account, including any email address you had typed. The record of which version of these terms and the privacy policy you accepted. The record of each term-change notice we sent you, and your newsletter subscription with the reason you gave if you ever unsubscribed. Your sign-in record itself - the email address on your GitHub account, which our sign-in provider passed to us when you signed in, your name, your avatar, your GitHub username, and the access token from your GitHub sign-in - and the account behind it, which we close at our sign-in provider. And you are removed from inside the stored descriptions of the repositories and search runs that mention you; those records belong to a recruiter and stay, minus you.
It signs you out, and that is the point rather than a side effect. Deleting the record that lets you log in ends the session you deleted from. We would rather sign you out than keep your email address and a working key to your GitHub account after you have told us to delete everything.
The sign-in record and the sign-out are the one part of this list that does not apply if the same login is also a recruiter account; 7.3 says what happens then.
7.3 If the same login is also a recruiter account
Your developer data goes exactly as 7.2 lists it. Your recruiter workspace and your sign-in record stay, and you stay signed in. Deleting your developer data is not a request to close a service you are paying for, and we do not read it as one. Your sign-in record - the email address on your GitHub account, your name, your avatar and the access token from your GitHub sign-in - stays because that is what the account you are still using runs on. We would rather say that plainly than let you read "we delete everything" and find out later.
If you want that record gone as well, close the recruiter account. That is a different button, on the recruiter side of your Account page; it refuses while a subscription is running, so that nothing is billed after the account is gone, and it gives you thirty days to change your mind where this one gives you ten seconds. The deletion dialog on the developer side tells you which of the two outcomes, 7.2 or 7.3, applies to your login before you confirm.
7.4 What survives
It stays deleted. An erasure the next search undoes is not an erasure, so we also put your numeric GitHub account id on a suppression list. The refusal to store you again sits underneath the whole product, in the database, rather than depending on each part remembering to check.
Everything that survives a deletion, all of it:
- Your numeric GitHub account id and the date, on the suppression list. Two columns, nothing else. To honour "forget me" we have to remember exactly one thing about you, and we would rather say so than let you find out. It is kept until one person removes it: you, by signing in with that GitHub account again and ticking the authorization box, which is a later consent and outranks it. Nothing a recruiter does, and nothing we do on our own, takes an id off that list.
- A record that the deletion ran - the same account id, the date, whether it succeeded, how many records it touched and which tables. No name, no username, no email.
- The reason you gave, and the address you gave for a reply, if you chose to give either. Both are kept with that record, in your own words, and the address is used for that reply and nothing else. Leave them blank and there is nothing to keep.
- Your consent receipts, marked withdrawn. Which wording version, when accepted, when withdrawn. This is what proves the earlier processing was consented to; destroying it at the moment of erasure would destroy the proof.
- Only if the same login is also a recruiter account: that account. Its workspace, its collections and notes, and the sign-in record behind it. Not a residue and not a technicality - a whole account, surviving because closing it is not what you asked for. Everything we held about you as a developer is still gone.
That is the whole list. Item 5 applies only to people who also use Thleo as a recruiter; if you do not, items 1 to 4 are the complete list for you. Signing in again after a deletion gives you a fresh, empty account with nothing carried over.
7.5 What a deletion cannot do
It does not change anything on GitHub - not your profile, not your repositories, not your links, nothing. It does not stop a recruiter opening your public GitHub profile; that is not ours to prevent, and what changes is that nothing they do there puts you back into our database. And it does not reach a file somebody already downloaded.
It does not withdraw the permission you gave GitHub when you signed in. We delete our copy of the access token; we cannot cancel the connection at GitHub's end, because the application it was issued to is our sign-in provider's rather than ours. If you want that gone as well, revoke it yourself at github.com → Settings → Applications → Authorized OAuth Apps. We would rather tell you that than let you assume we did it.
8. What we never do
Each line here is something the system cannot produce, not a promise about intent.
- We email you about exactly one thing without asking: a new version of these terms or of the privacy policy, at the address in 5.6, at most once per change (§11). Nothing else - no welcome message, no notification, no "a recruiter viewed your profile" - unless you tick the newsletter box in 5.6, and that stops the moment you untick it. If you type a contact address in 5.5, we do not use it at all - it exists for a recruiter to write to you, not for us.
- We never change what your profile says. There is no field anywhere in Thleo for editing a name, a bio, a location, a company, a picture or a link - not for you, not for a recruiter, not for us. What Thleo shows is what GitHub returned at the last refresh (§2), with the fields you unticked left out. If something is wrong, the fix is on GitHub, and it arrives here at the next refresh or when you press refresh on your Account page.
- We never ask for a GitHub password and never see one.
- We never read your private repositories or private activity, and the one private profile field we ask GitHub for is the email address on your account, for sign-in and for the notices in 5.6. We do not ask for access to anything else that is private.
- We never write to your GitHub account or your files. No code, no issues, no pull requests, no settings, no collaborators. Thleo can do one write on GitHub: star or unstar a repository, on the account of the signed-in person who clicked the button, at that moment. Nothing about that touches your account.
- We never sell your data, share it with data brokers, or use it for advertising.
- We never tell a recruiter what you chose. There is no "this person is hidden" notice and no "this field was withheld" marker. A field you withheld renders exactly like a field you never filled in, because a marker would broadcast the decision it exists to protect.
- We never take a contact address for recruiters from GitHub. Signing in gives our sign-in provider the email address on your GitHub account, and we keep it on your sign-in record to run the account (§7 deletes it). It is never shown to a recruiter and never copied into your profile. The only address a recruiter can see is one you typed in 5.5.
- We store only the links you ticked, and we delete each one the moment you untick it.
- We offer recruiters no export of any way to contact you. Not your links, not the address in 5.5. Recruiters can download what they have found - profiles, repositories, their own notes - and the fields each of those files may contain are fixed in our code, one named list per download, with no contact detail on any of them. The one thing that could still carry an address out of Thleo is what a recruiter typed in their own note (§6, limit 4) - their writing, not a field of ours, and our Terms of Service tell them not to put contact details there. This is a statement about the product as it is today, and it is the reason the rest of this page can promise anything: a downloaded file is the one copy we could not reach later if you asked us to. If we ever build an export that carries contact details, it will ask you for that in plain words, on its own - nothing you ticked in §5, and nothing in these terms, authorizes it.
9. What we ask of you
Short, and none of it is a trap:
- Use your own GitHub identity. A developer account is for the GitHub account you signed in with. Do not sign in as someone else, and do not ask us to change or delete another person's data unless you are authorized to act for them.
- Type your own address in the email box, if you use it at all.
- Do not attack the service. No probing it for weaknesses, no automated scripting against it, no attempts to reach the recruiter side of the product or another person's data from a developer account, and no working around GitHub's rate limits through us.
- Do not use the account controls to misrepresent yourself. We read your profile from GitHub, so there is not much room here - but the boxes decide what is shown, not what it says, and using the product to impersonate somebody is not on.
- Your GitHub account is still governed by GitHub's terms, and nothing here changes them.
If you think you have found a security problem, please tell us at support@thleo.app rather than demonstrating it.
10. Ending this
You end it. Set yourself Hidden and stop, untick the authorization box, or delete everything under §7. None of these requires telling us why, and none of them takes an explanation we get to weigh.
We end it. We may close a developer account that is signing in as somebody else, attacking or probing the service, using the developer side to get at recruiter data, or breaking the law. If we do, we delete the account's data the way §7 describes, and the same survivors apply.
We will not tell you by email. §8 lists the one thing we write to you about without asking, and this is not it. The account simply will not work when you next sign in. That is an unsatisfying answer and it is the true one.
11. Changes to these terms
Every version of this document stays publicly readable, so you can see exactly what changed and when. Nothing is edited in place after it goes live: a change is a new dated version, and the old one stays up beside it.
A new version of these terms or of the privacy policy is announced at least 14 days before it takes effect, by one email to the address in 5.6, with a link to the new version beside the old one, and by a notice inside your account. You can accept it there with one click. If you do neither and keep using Thleo after that date, that is your acceptance of the new version, and we record it as such, with the date you were notified. If you would rather not accept it, §7 lets you delete everything before it takes effect.
The authorization in 5.2 is the exception, and cannot be accepted for you. It is consent, not a contract. The box records which version of its text you accepted; any change to that text - however small - is a new version, a receipt for an older version stops counting, the controls lock, and you are asked to tick it again. Nothing you do or fail to do ticks it on your behalf. That is the design, not a side effect: consent to a sentence you never read is not consent.
We cannot notify developers who have no account, because we hold no way to reach them and holding one is the harm we avoided in the first place. That is another reason this page is public and permanent.
12. What we do not promise
- Being on Thleo is not a job application, and it is not an offer. No recruiter is obliged to contact you, and being findable here changes nothing about your chances.
- "Recruiter" means somebody who signed in with GitHub and holds a recruiter subscription, paid or on its free trial. We do not independently verify anybody's employer or their reason for searching. Our Terms of Service restrict what they may do with what they find, and we can enforce those terms against an account - but you should read "recruiter" as a customer of ours, not as a credential we checked.
- The figures are estimates. Profile confidence, language proportions and skill percentages are our arithmetic over your public repositories. They are not a measure of your ability, and our Terms of Service forbid recruiters from using them as the sole basis for a decision. We cannot stand behind a human judgement made elsewhere.
- The service is provided as it is, without an uptime guarantee. Parts of it depend on GitHub, WorkOS, Supabase, Vercel, Upstash and Resend, which delivers the email in 5.6, whose availability we do not control.
- Nothing here is a warranty about GitHub's data. We show what GitHub publishes. If it is wrong, the fix that lasts is at GitHub - we mirror it. We will delete our copy in the meantime if you prefer.
- Support is in English, and in no other language. We read and answer support mail in English only. A message in another language gets one reply, in English, asking for English, and we do not translate in either direction. This limits the languages we answer in, not who may use Thleo.
- What we owe you if something goes wrong is limited. The developer account is free. To the maximum extent the law allows, we are not liable to you for loss arising from it, and never for indirect or consequential loss. That exclusion does not reach liability for intent or gross negligence, for death or personal injury, for our obligations under data-protection law, or for anything the law where you live does not let us exclude.
13. Governing law, and how to reach us
These terms are governed by the laws of [JURISDICTION - to be completed with legal counsel], and disputes will be resolved in the courts of [VENUE]. The service is operated by [LEGAL ENTITY NAME], which is the data controller for the processing described here. The three brackets are filled by counsel before sign-ups open; every legal document here carries the same three, and nothing else in these terms depends on the choice.
Before a court, write to us. Tell us what went wrong and give us a reasonable chance to put it right; if we do not, or you are not satisfied, the courts above are open to you. You never have to write to us before complaining to a data protection authority, and nothing here changes GitHub's own terms, which govern GitHub itself.
Whatever is filled in above, this does not take away rights you have where you live. If you are in the EU, the UK, or anywhere else with data-protection law of its own, that law applies to you and we apply the same process to everyone regardless of where they are.
Write to us at support@thleo.app - for asking what we hold, for a security report, or for anything else in this document. Not for deleting your data: that is the button in §7, and 7.1 says why an email cannot replace it. One address, monitored by the Thleo team. We have not set a guaranteed reply time and will not claim one we do not measure.
You also have the right to complain to the data protection authority where you live. You do not have to talk to us first.
See also: the Privacy & Security policy, the developer FAQ, the recruiter-facing Recruiter Terms of Service, and the glossary for the words these documents use in a fixed sense. Thleo is at thleo.app.