Recruiter Terms of Service

The terms that govern a recruiter's use of Thleo

The agreement between you and Thleo about your recruiter account, your workspaces and billing, and what you may do with what you find.

These terms are for recruiters. If you also hold a developer account, the Developer Terms of Service cover that side, and they apply to you separately.

Table of contents

  1. Acceptance of These Terms
  2. Accounts
  3. Workspaces and Teams
  4. Subscriptions, Free Trial, and Billing
  5. Seat and Billing-Interval Changes: Charge Authorization
  6. Cancellation, Refunds, and Disputes
  7. Acceptable Use
  8. Your Data
  9. Service Availability and Changes
  10. Support Language
  11. Disclaimers, Limitation of Liability, and Indemnity
  12. Ending your account on Thleo
  13. Governing Law and Contact
  14. Changes to These Terms
  15. General
  16. Data Processing Addendum

1. Acceptance of These Terms

Thleo is a platform that helps tech recruiters discover, evaluate, and organize software developers, using public GitHub data about developers who have chosen to be shown to recruiters. You accept these Terms of Service and our Privacy & Security policy by continuing past the sign-up page as a recruiter, beneath the sentence that says you agree to them, and we record which version of each you accepted and when. Your use of Thleo is governed by them from then on. By continuing you also confirm that you are at least 18 years old. If you use Thleo on behalf of a company, you represent that you have authority to bind that company to these terms; where a company pays for a team (§3), that company is our customer for the team workspace, and the person who paid acts for it.


2. Accounts

2.1 Signing in

Thleo accounts are created by signing in with GitHub. Sign-in runs through WorkOS, which handles the GitHub OAuth round trip for us; we never ask you for a password and never see one. You are responsible for the security of your GitHub account and for all activity performed through your Thleo session.

The email address on your GitHub account is your sign-in address. We keep it on your sign-in record to run the account, and the one-time codes that authorize a charge (§5) go there and only there, because they move money and the address that proves who you are is the one to send them to. There is no field in Thleo to change it, and it is never shown to a developer or copied into any candidate data.

2.2 Where Thleo reaches you, and a newsletter only if you ask

On the Preferences tab of your Account page there is a box, Address for notices. It is where we write to you, and we write for exactly one reason without asking: to tell you that these terms or the privacy policy have a new version (§14). It starts as your sign-in address, because that is the one address every account has; change it if you would rather be reached somewhere else. It has no checkbox, because a person cannot opt out of being told the agreement they hold has changed - only choose where. The codes in §5 do not go to this address; they go to your sign-in address, as 2.1 says.

Below it is one box, and it starts unticked: the newsletter. Occasional mail about new features and how the product is doing, never more than a few times a month. Ticking it is your consent to that and to nothing else; the exact sentence beside the box is what we record, with the date. Every issue carries a one-click unsubscribe link that works without signing in, and unticking the box does the same. Nothing about your account or your subscription changes either way, and the box is never on the signup page: agreeing to these terms and agreeing to be written to are two different things.


3. Workspaces and Teams

Thleo separates your data into workspaces. Your personal workspace is private to you. A team workspace is shared: every active member of the team can view and edit everything created inside it - collections, saved candidates and repositories, notes, tags, filter templates, linkages and the rest. Deleting shared data is restricted to the item's creator and team admins.

  • A team comes into existence when a recruiter pays for a team subscription in the name they give it at checkout. The company behind that name is the customer for the team workspace; the recruiter who paid is the team's admin and acts for it, and the team workspace is a separate workspace from their personal one, with its own subscription. The team grows by seats: the team admin pays for each seat (§5), and each paid seat can hold one member or one pending invitation.
  • The admin role can move. If the admin leaves the company or can no longer act, the company asks us from the email address on the team's billing account, naming the member who takes over, and a person moves the role by hand. The team, its data and its subscription continue unchanged. There is no button for it, and we do not move the role on a request from anybody else.
  • Each active member and each pending invitation consumes one paid seat - including the team admin, who holds a seat from the moment the team exists, whether or not they ever open the team workspace. That seat cannot be given to somebody else.
  • Once every paid seat is taken, the application refuses to send another invitation until a seat is freed or added.
  • Team admins may remove members and revoke invitations. Data created in the team workspace belongs to the company that pays for the team and remains in the workspace when a member leaves.
  • Governance actions in a team (members joining or being removed, seat changes, deletions of shared collections) are recorded in an append-only activity log readable by the team's admins. An entry is written by the system at the moment the action happens and is never edited afterwards, by anyone: there is no screen for it, the database refuses updates and deletions from the application, and Thleo - the people who run it and the software itself - does not alter entries by hand or by any other means - not to help a team and not to harm one. What the log says is what happened.

4. Subscriptions, Free Trial, and Billing

Thleo is a paid service. Payments are processed by Stripe; we never store card numbers.

  • Individual plan: a personal subscription unlocking your personal workspace.
  • Team plan: a per-seat subscription (billed monthly or annually) paid by the team admin, unlocking the team workspace for every member. The same person may hold a personal subscription, belong to teams, and own teams simultaneously.
  • Free trial, once per plan. Your first individual subscription starts with a 14-day free trial, and so does the first team subscription you pay for: two separate trials, because they are two separate billing accounts. Checkout asks for a payment method before the trial starts. When the trial ends, the subscription starts and that payment method is charged the plan price, and it renews from then on until you cancel. Cancel in the billing portal before the trial ends and you pay nothing. A later subscription of the same kind - after a cancellation, or a second team - starts without a trial. The Subscription tab of your Account page shows the day your trial ends and the amount that will be charged on it.
  • Prices, tax, and the founding price. Prices are in US dollars and exclude tax; where we are registered to collect tax in your country, Stripe adds it at checkout from your billing address and shows it before you pay. The price at checkout today is the founding price: it is held for 24 months from your first subscription, for as long as that subscription stays active, and the regular price is printed beside it on the pricing page so you never learn it at a renewal.
  • Price changes. We may change a price. A change never applies inside a period you already paid for, and it reaches you only at a renewal at least 30 days after we told you about it, by email to your address for notices (2.2). You can cancel before that renewal in the billing portal and pay nothing more.
  • Subscriptions renew automatically at the end of each billing period until canceled. The Subscription tab of your Account page shows your plan, its status, the current period, and what happens next - a renewal, a trial ending, or an access end date - so you never have to infer it.

5. Seat and Billing-Interval Changes: Charge Authorization

Changes that move money are protected by an explicit confirmation step, and completing that step is your authorization of the resulting charge:

  • Adding seats or switching billing interval requires a one-time code emailed to the requesting admin's sign-in address (2.1). The email states the exact change and the resulting plan total. If you lose access to that inbox, recover it with your email provider or GitHub: we cannot send the code anywhere else, and we cannot make the change for you. Entering that code in the application constitutes your electronic authorization of the change and of the prorated charge described in that email.
  • Codes are single-use, expire after 10 minutes, and can only be redeemed by the same admin who requested the change. Five wrong entries lock the operation; request a new code to start over.
  • Reducing seats never triggers a charge. Your subscription continues; from the next invoice on it is billed for the smaller number of seats. The removed seats were already paid for up to the end of the current period, so the remainder of that period is not lost: Stripe records it as a credit on your billing account and subtracts it from your next invoice.
  • Every money-moving operation is recorded with a traceable operation id, the exact authorization wording version shown to you, the price at the time, your confirmation timestamp, and the resulting Stripe invoice. These records are retained and may be used as evidence in billing disputes.

6. Cancellation, Refunds, and Disputes

  • You may cancel any subscription at any time through the billing portal (Account → Subscription → Open billing portal). Cancellation stops future renewals; access continues until the end of the already-paid period. Cancelling during a free trial ends the trial with no charge.
  • Except where required by law, payments for the current billing period are non-refundable once the period has started.
  • Cancelling is yours to do, in the billing portal. We do not cancel a subscription on a request made by email, because an email cannot be verified the way a signed-in action can.
  • If you buy as a consumer in the EU or the UK, the law gives you 14 days to withdraw from a contract made at a distance. The checkbox on Stripe's checkout page is where you ask us to start the service at once and acknowledge that the right ends when it does; your first subscription also carries the free trial above, which is longer than those 14 days. Nothing in this section takes away a right the law where you live gives you.
  • If you believe a charge is incorrect, email support@thleo.app with the subject "Incorrect charge" before disputing it with your card issuer - most issues are resolved quickly, and the operation records described in §5 will be provided in any dispute.

7. Acceptable Use

  • Use Thleo only for lawful recruiting and talent-evaluation purposes connected to a genuine hiring process. Candidate information may be shared only inside your authorized workspace and with the employer or hiring-team members involved in that process.
  • Respect GitHub's Terms of Service: Thleo surfaces publicly available GitHub data through GitHub's official API and is subject to GitHub's rate limits.
  • Do not sell, resell, license, publish, publicly redistribute, or use Thleo or candidate information as a list-brokerage, data-brokerage, or contact-list service. A limited handoff to the relevant employer or hiring team under the first bullet is permitted; onward sale or unrelated reuse is not.
  • Do not use data obtained through Thleo for spam, bulk unsolicited outreach, harassment, stalking, or any purpose unrelated to the hiring process for which you accessed it.
  • Do not try to infer fields a developer withheld, bypass profile visibility, reidentify or re-add a suppressed developer, or use an old export or changed username to circumvent a withdrawal, objection, or removal request.
  • Treat profile confidence, proficiency estimates, popularity, collection-demand signals, and future code analysis as decision-support context only. Do not use a Thleo-derived measure as the sole or determinative basis for automatic rejection, ranking out, or a hiring decision.
  • Do not use Thleo or its data to discriminate unlawfully or otherwise violate data-protection, employment, labor, or equal-opportunity law. You remain responsible for the human hiring decision and for verifying whether your use is lawful where you operate.
  • Protect downloaded exports and other candidate records against unauthorized access. Delete them when the relevant hiring purpose and applicable legal retention period end, and comply promptly with a verified correction, withdrawal, or removal instruction from Thleo. Downloaded files are outside Thleo's technical control and are not automatically recalled or deleted when an in-product profile changes.
  • Contact details a developer chose to show you carry obligations that travel with the details, not with the screen you saw them on. An address or link a developer enabled may be used only to approach that person, once, about the hiring process you accessed them for; if they do not answer, or ask you to stop, that is the end of it. A link they published on GitHub is theirs to publish there, and it does not become a mailing list because Thleo showed it to you. If they ask you to stop contacting them, or to delete what you hold about them, act on it promptly and directly - the request does not have to reach you through Thleo, and Thleo cannot pass on a request it never sees. Do not sell, publish, redistribute, or pass a developer's contact details to anyone outside the hiring team for that role. Delete the details you hold when that hiring purpose and any applicable legal retention period end. A developer turning a detail off in Thleo stops Thleo showing it; it does not reach a copy already in your notes, your inbox, or your applicant tracking system, which is why this obligation is yours alone: Thleo has no way to reach, and no way to delete, a copy that has left it.
  • Do not place unnecessary contact details, sensitive information, or information unrelated to the hiring purpose into free-form notes.
  • Do not attempt to circumvent seat limits, share accounts, rotate GitHub tokens to evade GitHub rate limits, resell access, scrape the service, probe its security, or interfere with other customers.

We may investigate suspected misuse, restrict exports or other features, require deletion or correction of improperly used data, and suspend or terminate an account or workspace that violates this section.


8. Your Data

8.1 Data you create

You retain ownership of the data you create in Thleo (collections, notes, tags, and any other content you create). You grant us the license needed to store and process it to operate the service. Data in a team workspace is controlled by the company that pays for the team, not by individual members. For that data we act as your processor; §16 is the contract for it. Our data practices and the GitHub permissions we request are described in the Privacy & Security policy; closing your account is 12.1.

Deleting is not the end, for thirty days. A collection, tag, note or filter preset you delete moves to your recycle bin, where it stays for thirty days and can be restored to the workspace it came from. After that a nightly job deletes it for good, and nobody can recover it. Things that are assembled rather than authored - a membership, an assignment - have no bin and go at once.

Notes are free text, and the outreach log beside them is your own record of when you were in contact with a candidate, through which channel, what came of it, and when you mean to follow up; Thleo shows those follow-up dates back to you on a calendar and on the candidate's card. Whatever you type into either - including anything about a candidate that Thleo never asked you for - is content you author and control. Thleo provides no field for candidate contact details on the recruiter side and asks you not to improvise one; a channel in the log is a label, never an address.

A note about a developer is deleted with them, and so is your outreach log about them. When a developer deletes their data (8.2), every note and every outreach log entry about them goes too, in every workspace, not only yours. A note here is therefore not a lasting record of an interview or of a decision. If your organization needs one, it belongs in your own systems, on your own lawful basis; Thleo cannot keep it for you, and will not warn you before it goes.

8.2 Developer profile data, and where it comes from

Read this first, because it governs everything else in this section. Thleo displays, counts and stores developer profile information only on that developer's consent. A developer's information is available to you only while all three of the following hold at once:

  1. the developer holds a Thleo developer account, created by them with their own GitHub sign-in;
  2. that account's visibility is set to Visible to recruiters or Public - a new account starts Hidden; and
  3. the developer holds a current, un-withdrawn recruitment authorization for the version of that authorization wording in force today.

If any one of them fails, a search for that developer returns the same "no profile" result as a username that does not exist on GitHub, and nothing new about them is stored or counted - the write is refused at the database rather than by a check somewhere in the code. If a developer satisfied all three before and then stopped, what Thleo already held is emptied at that moment; the last bullets in this section say what that reaches and what it leaves. This applies to every developer, including the overwhelming majority who have never held a Thleo account: their absence from your results is the rule working, not a gap in coverage. Legitimate interests is not a basis on which Thleo displays any developer information.

Public differs from Visible to recruiters in one thing, and it does not change what you see: a developer who chose Public also has a page at thleo.app/developers/their-username that anyone with the link can open without signing in. It shows exactly what you see, and nothing more.

You must not attempt to work around this. §7's prohibition on circumventing privacy controls covers reconstructing, retaining, re-importing, or sharing developer information that Thleo has stopped showing you, including from your own earlier exports.

Subject to that rule, developer-related information in Thleo comes from four sources. Thleo does not buy candidate data from data brokers or combine it with scraped profiles from other sites.

Everything Thleo reads from GitHub comes through GitHub's official API, on one host, api.github.com: the GraphQL API for everything, and one documented REST endpoint for the public organization list, which GraphQL will not return without a permission Thleo does not request. Thleo does not crawl github.com and does not read HTML pages; there is no scraping code in this product to switch on. The Developer Terms make the same commitment to the people you are searching.

  • GitHub-derived information. Public profile fields, profile and repository links, public repository metadata and content, public contribution activity, public organizations, and account counts are read through GitHub's official API. Thleo cannot obtain a private repository or field that GitHub does not return to the signed-in user.
  • Developer-authored information and choices. A developer may type an optional contact email directly into Thleo and separately choose whether recruiters may see it. Developers also control their Thleo visibility and individual profile/contact disclosures.
  • Recruiter-authored workspace information. Collections, notes, tags, and hiring-workflow context are created by recruiters and their teams; GitHub does not supply them.
  • Thleo-derived information. Language proportions, profile-confidence and proficiency estimates, popularity rankings, and search/save/collection-demand signals are calculated by Thleo from public GitHub inputs or activity on Thleo. They are not statements made by GitHub or by the developer.

What this means in practice:

  • GitHub-derived fields remain subject to developer controls. A blank field may be blank on GitHub or may have been withheld through Thleo's developer controls, and a developer who is absent entirely may have no account, be hidden, or have withdrawn their authorization. Thleo deliberately does not tell you which. Do not infer, solicit, or attempt to recover a value or a person Thleo does not show you.
  • The "Social Media" row appears when you look. A candidate card shows no such row until you open the card or hover over it, because that is when Thleo reads the developer's links; it then shows the links they enabled, or the word "None". "None" is the answer for a developer who publishes no links and for one who has enabled none of them, identically, because a marker that told them apart would announce the decision the controls exist to protect.
  • Candidate email is not imported from GitHub. The optional-email feature is for an address the developer provides directly and separately enables for disclosure. It has nothing to do with your own sign-in address (2.1).
  • GitHub-published websites and social links are stored only once the developer enables each one. Thleo keeps a copy of each link a developer has explicitly enabled, so that displaying a card does not require a request to GitHub per link. A link the developer disables is deleted in the same write that records the decision; a link they remove from GitHub is removed from Thleo at the next refresh of that profile (8.3), which is not instantaneous. No Thleo export contains a developer's contact details in any format - not their links, not the optional email above. Every export builds its rows from a fixed, named list of fields, and no contact detail appears on any of those lists. Free-form notes you wrote are the exception, because they are your text rather than a field Thleo populates, which is one reason §7 asks you not to put contact details in them. If Thleo ever offers an export that carries contact details it will require the developer's separate, explicit opt-in; it is not covered by the authorization that lets you see the detail on screen.
  • Derived signals are limited context. Popularity and demand signals describe activity on Thleo, while profile-confidence and proficiency estimates describe the completeness or composition of observable public repository data. None proves job fitness, interest in a role, years of experience, or authorship, and §7 prohibits treating one as determinative.
  • What is cached exists only while consent does. Thleo caches a profile only for a developer who satisfies conditions 1 to 3 at the start of 8.2, and that copy is re-read from GitHub only at the moments in 8.3 - so what you see is the most recent read rather than a permanent record, and it may be behind what GitHub shows right now. Going hidden and withdrawing an authorization are different acts. A developer who goes Hidden stops being displayed to every recruiter on Thleo - not only to you: in search, and in every collection anyone had saved them to - and Thleo deletes nothing: hiding is reversible by design, so their settings and the values behind them wait for them, shown to nobody in the meantime. A developer who withdraws their authorization - or whose authorization is superseded by new wording - stops being displayed and Thleo empties what it held: the cached profile fields, the copies of them inside every recruiter's search history, and every contact link that developer had switched on. What survives a withdrawal is their account, their own settings, the dated record of the consent and the withdrawal, and figures derived from their public repositories. Thleo does not delete a cached profile on age alone, so the routes to removal are the developer's own withdrawal or their deletion, next.
  • A developer can delete everything Thleo holds about them, with one button on their signed-in developer account: no request to file, no approval to wait for. It needs their GitHub sign-in, and that is the whole of our identity check: a request by email cannot be told from a stranger's, so we do not act on one, and we cannot delete on behalf of somebody who can no longer sign in to the GitHub account in question. This is the right to erasure under Article 17 of the GDPR, and we apply it to everyone regardless of where they live. Withdrawal and deletion are different acts: withdrawal ends the display and empties the profile content Thleo held, while deletion additionally removes the records themselves rather than leaving emptied rows, along with the derived analysis and the developer's own account. Deletion removes the candidate cache, every stored contact link, derived analysis, recruiter search-history and collection membership, embedded copies inside saved repository data, and recruiter-authored notes and tags linked to that candidate - your writing about them goes with them. Minimal suppression, completion-audit, optional-reason, reply-address, and authorization-receipt evidence may remain as described in the Privacy & Security policy. Deletion does not alter the public source on GitHub and cannot recall a file already downloaded; §7 requires you to act on a verified removal instruction.

Your use of this data is subject to §7 and to applicable data-protection and employment law. Thleo gives you access to public information. It does not determine, and cannot determine, whether your particular use of it is lawful where you operate.

8.3 When the copy of a developer is refreshed

Thleo keeps a copy of what it reads from GitHub, so that your page does not need a request to GitHub every time it loads. That copy is re-read from GitHub - a refresh - at these moments and at no other: when the developer opens their own Account or Explore page and the copy is more than six hours old; when you search their username and it is more than an hour old; when you press refresh on their card; and when you open a collection they are saved in and the copy is more than fourteen days old; and whenever the developer acts themselves - pressing Refresh from GitHub on their own Account page, or changing any of their boxes, which re-reads the profile under their new choices. There is no timer: nothing refreshes a profile nobody is looking at, and nothing deletes a cached profile on age alone. Wherever this document says "at the next refresh", this is what it means.

Two consequences. A change the developer makes on GitHub arrives here at the next refresh, so between refreshes you may be looking at what GitHub said an hour, or fourteen days, ago; if it matters, press refresh, which is rate-limited, so use it when it counts. And the developer's own controls do not wait for one: a field, a link, or the authorization they untick acts on the copy immediately, whatever GitHub still says. A refresh only ever brings the copy closer to what GitHub publishes, never past what the developer allows.

When Thleo's copy of a developer profile is refreshed GitHub publishes the developer's profile. Thleo keeps a copy holding only the fields the developer allows. The copy is re-read from GitHub only at these moments: the developer opens their own Account or Explore page and the copy is older than six hours; you search their username and it is older than one hour; you press refresh on their card; you open a collection they are saved in and it is older than fourteen days. The developer's own refresh button and every box change also re-read it. There is no timer. The developer's own boxes act on the copy immediately, and then re-read. The developer's GitHub profile published by them, on GitHub refresh Thleo's copy only the fields they allow What you see in search, on cards, in collections A refresh happens at these moments, and no other 1. The developer opens their Account or Explore page - if older than 6 hours 2. You search their username - if older than 1 hour 3. You press refresh on their card - always 4. You open a collection they are saved in - if older than 14 days 5. The developer presses Refresh from GitHub, or changes any box - always There is no timer. Nothing refreshes a profile nobody is looking at. Their boxes do not wait The developer unticks a field, a link, or the authorization box → acts immediately, whatever GitHub still says (and then re-reads GitHub for them)


9. Service Availability and Changes

We work to keep Thleo available and fast, but the service is provided "as is" without uptime guarantees. Features may evolve; we will not remove paid functionality mid-period without a reasonable substitute or a prorated remedy. Some functionality depends on third parties (GitHub, Stripe, WorkOS, Supabase, Vercel, Upstash, and Resend) whose availability we do not and cannot control.


10. Support Language

Thleo provides support, communications, and documentation exclusively in English. We reserve the right to respond only to inquiries submitted in English and are under no obligation to translate support requests, replies, or any part of the service into another language.

This applies to support communications and does not restrict who may use Thleo - the product itself is available to anyone able to use it in English, regardless of nationality or country of residence.


11. Disclaimers, Limitation of Liability, and Indemnity

Thleo presents GitHub-derived and developer-provided information together with recruiter-authored context and Thleo-derived analysis; we make no warranty about its accuracy or completeness, and hiring decisions remain entirely yours. To the maximum extent permitted by law, our total liability for any claim arising out of the service is limited to the amounts you paid us in the twelve months preceding the claim, and we are not liable for indirect, incidental, or consequential damages.

That cap and that exclusion do not apply to liability for intent or gross negligence, for death or personal injury, for a breach of §16, or to any liability the law where you live does not allow to be limited.

You indemnify us against claims, fines and costs brought by a third party - a developer included - that arise from your use of candidate information in breach of §7, §8 or the law that applies to you. We tell you about such a claim promptly, let you conduct the defence, and do not settle it without your agreement.


12. Ending your account on Thleo

12.1 Closing your account

Closing a recruiter account is a button, on the Danger Zone tab of your Account page, with one difference from the developer's: a recruiter is a paying customer who may change their mind, so the button closes the account at once and deletes it thirty days later. Three steps, in this order:

  1. Cancel your subscription in the billing portal (Subscription tab). Cancelling stops future renewals; your access continues until the end of the period you already paid for, or until your free trial ends. This comes first because a subscription still running after the account is gone would keep billing a person who can no longer sign in to stop it, and the button refuses to run while one is running; a subscription you have already set to cancel at the end of the period does not stand in the way. If you run a team, remove its members and cancel its subscription too, or have the admin role moved first (§3): the button also refuses while you still run a team that has other members or a running subscription.

  2. Press Delete my account. You type a word to confirm you have read what goes, a ten-second countdown runs with a Cancel beside it, and when it ends the account is closed: you are signed out everywhere, you leave every team you belonged to, and nobody can open your workspace. Nothing is destroyed yet. Sign in again within thirty days and the account is restored, everything as you left it except your team memberships, which need a new invitation. After thirty days a daily job deletes it, and nobody can recover any of it: your personal workspace - collections, saved candidates and repositories, notes and outreach logs, tags, filter templates, search history, pipeline stages, custom seniorities and interview stages, bulk-import and deep-search records - your settings, your recruiter role, and your sign-in record. If the same login also holds a developer account, that account and the sign-in record stay, as the Developer Terms of Service say in reverse; that side has its own button.

    What stays with a team you belonged to: everything you created there - collections, saved candidates and repositories, notes, tags, pipeline stages, filter templates, custom seniorities and interview stages, and the links you made between collections - because it belongs to the company that pays for the team (§3). Things that were filed under your name pass to the team's admin. The one team-scoped thing that goes with you is your search history, which is your own activity rather than the team's work. A team you created and were the only member of is deleted with you. What survives everything: the §5 operation records and their Stripe invoices, Stripe's own records on Stripe's retention, and a record that the deletion ran - the dates, whether it succeeded, how many rows and which tables, and the reason and reply address you gave if you gave them - carrying your account ids and nothing else about you.

    A request by email does nothing: an email cannot be verified the way a signed-in action can, so the button is the only route, and we cannot delete on behalf of somebody who can no longer sign in to the GitHub account in question.

  3. Revoke Thleo at GitHub, if you want the connection gone too. Deleting the account deletes our copy of your GitHub access token, but we cannot cancel it at GitHub's end, because the application it was issued to is our sign-in provider's rather than ours. Revoke it yourself at github.com → Settings → Applications → Authorized OAuth Apps.

12.2 Termination by us

We may suspend or terminate accounts that violate these terms (including §7), with a refund of any unused prepaid period except in cases of serious abuse. Upon termination, §5 records survive as described in the Privacy & Security policy.


13. Governing Law and Contact

These terms are governed by the laws of [JURISDICTION - to be completed with legal counsel], and disputes will be resolved in the courts of [VENUE]. The service is operated by [LEGAL ENTITY NAME]. The three brackets are filled by counsel before sign-ups open; every legal document here carries the same three, and nothing else in these terms depends on the choice.

Before a court, write to us. Tell us what went wrong at support@thleo.app and give us a reasonable chance to put it right; if we do not, or you are not satisfied, the courts above are open to you. Nothing here stops you from going to a consumer body or a data protection authority at any time, and nothing here changes GitHub's own terms, which govern GitHub itself. Questions about these terms go to the same address.

See also: the Privacy & Security policy, the recruiter FAQ, the developer-facing Developer Terms of Service, and the glossary for the words these documents use in a fixed sense.


14. Changes to These Terms

Every version of this document stays publicly readable on this page's version history, so you can see exactly what changed and when. Nothing is edited in place after it goes live: a change is a new dated version, and the old one stays up beside it.

A new version of these terms or of the privacy policy is announced at least 14 days before it takes effect, by one email to the address in 2.2, with a link to the new version beside the old one and a short list of what changed, and by a notice inside your account. You can accept it there with one click. If you do neither and keep using Thleo after that date, that is your acceptance of the new version, and we record it as such, with the date you were notified. If you would rather not accept it, cancel and close your account (12.1) before it takes effect.


15. General

  • Assignment. You may not transfer this agreement without our written consent. We may transfer it to a successor that takes over the service, and we tell you when we do.
  • Force majeure. Neither of us is liable for a failure caused by something outside our reasonable control - an outage at a provider in §9, a network failure, a natural event, an act of a public authority - for as long as it lasts.
  • Severability. If a clause is unenforceable, the rest stands, and the clause is read as narrowly as it needs to be to stand.
  • Entire agreement. These terms, the Privacy & Security policy and §16 are the whole agreement between us about Thleo. Nothing said outside them, on a call or in a support reply, changes them.
  • No waiver. Not enforcing a clause once is not giving it up.
  • Survival. The §5 records, §7, §8, §11, §13, this section and §16 survive the end of the agreement for as long as they have anything to govern.
  • Sanctions. You may not use Thleo where, or on behalf of anybody for whom, the law forbids us to provide it, including under sanctions that bind us.
  • Feedback. If you send us ideas about the product, we may use them without owing you anything, and you gain no right in the product because of them.

16. Data Processing Addendum

This section is the contract that Article 28 of the GDPR requires between a controller and its processor. It applies to every recruiter account, personal or team, and it is accepted with the rest of these terms.

Who is what. For a developer's profile - the copy from GitHub, the links they ticked, the figures we work out - Thleo is the controller, on the developer's consent (8.2). For what you write about a candidate - notes, tags, collection membership, pipeline stages, search history - you, or the company you act for, are the controller, and Thleo is your processor: we hold it for you, on your instructions, for your hiring purpose and nothing else.

Subject matter, duration, nature and purpose. Storing the recruiter-authored data above and showing it back to you and your team, for the life of your account, so that you can run a hiring process.

Types of data and data subjects. Free text and labels about developers who are shown to you, attached to the GitHub username they are about.

Your instructions. Your instructions are these terms and what you do in the product: create, edit, delete, export. We tell you if we believe an instruction breaks the law.

Confidentiality and security. Access to the data is limited to the people who run Thleo, who are bound to keep it confidential, and it is protected by the measures in section 5 of the Privacy & Security policy.

Sub-processors. The providers listed in section 6 of the Privacy & Security policy, and only those. A new one is announced as a new version of that policy at least 14 days before it starts, by the notice in §14; you may object by closing your account (12.1) before it takes effect.

Assistance. Within reason, we help you answer a data subject's request that reaches you about data we hold for you, and we help with a data-protection impact assessment or a consultation with a supervisory authority.

Breaches. We tell you without undue delay after becoming aware of a personal-data breach that affects data we process for you, with what we know at the time, so that you can meet your own 72-hour duty.

Deletion. Thirty days after your account closes (12.1), we delete the data we processed for you; what survives is what 12.1 names. A developer's own deletion (8.2) deletes your notes about them, and that is an instruction we take from the developer, not from you.

Audit. We answer your reasonable written questions about how we meet this section and make available the information needed to show it. A service of this size does not offer on-site audits; if a supervisory authority requires one, we cooperate with it.

Transfers. Where a provider in section 6 of the policy processes data outside the EEA or the UK, the mechanism is the one that section names for it.

Liability. §11 applies to this section, with the carve-out §11 makes for it.

Version 2026-09-04.1 (current)