Legal
Privacy Policy
- Last updated
- September 10, 2026
- Applies to
- Scout for Jira Cloud
- Jira scopes
read:jira-work- Data controller
- Scout
On this page
Who this covers
Scout is an automated code-review agent. It reads a pull request, the repository around it, and the Jira issue linked to it, and publishes a review back to the pull request. It reaches Jira through an Atlassian Forge app installed on your site (app id ari:cloud:ecosystem::app/3d369f25-f2bc-42be-9b55-239abfe7a143), and reaches your code through a GitHub App you install on the repositories you choose.
This policy covers the Forge app, the Scout web dashboard, and the Scout backend service that connects them. It does not cover Atlassian, GitHub, or any other third-party service you use — their own privacy policies govern those.
For the purposes of the GDPR, Scout is the data controller for account data, and a data processor acting on your instructions for the Jira and repository content it reads on your behalf.
What we collect
2.1 Account data
You sign in to the Scout dashboard with GitHub. From that sign-in we store your name, email address, GitHub user id, GitHub username, and avatar URL.
2.2 GitHub installation data
When you install the Scout GitHub App we store the installation id, the account it was installed on and its type (user or organization), whether you selected all repositories or a subset, and the names of the selected repositories.
2.3 Jira connection data
When you connect Jira from the dashboard via Atlassian OAuth 2.0 (3LO) we store your Atlassian account id, the account email address, and the id, name and URL of the site you selected.
2.4 Forge installation data
When the Forge app is installed on a Jira site, it registers that installation with our backend. We store the site base URL (for example your-team.atlassian.net), the Forge installation identifier, and the unique web-trigger URL Forge generates for that installation. That URL is how our backend asks your site for issue data.
2.5 Content read on demand
To produce a review, Scout reads — at the moment of the review, through official Atlassian and GitHub APIs:
- Jira issue content — issue key, summary, description, status, issue type, priority, assignee, and created/updated timestamps for the issue linked to the pull request, or for issues in a project you name.
- Repository content — the pull request diff, its title and description, and the surrounding source files needed to understand the change and what it can affect.
This content is processed to generate the review and returned to the requester. We do not build a permanent copy of your Jira projects or your source code.
2.6 Operational logs
The Atlassian Forge platform and our backend record standard operational logs — timestamps, request outcomes, and error messages — which we use to run the service and diagnose faults. Logs may incidentally contain identifiers such as a site URL or an issue key.
2.7 What we never collect
- Atlassian or GitHub passwords — authentication is delegated to OAuth and to the Forge platform.
- Payment card details.
- Analytics, advertising, or cross-site tracking identifiers.
How we use it
- To deliver the product's core function: reading the pull request and the linked Jira issue, and publishing a review.
- To route each request to the correct Atlassian installation and the correct GitHub repository.
- To authenticate you and keep your dashboard session and connection status accurate.
- To monitor reliability, diagnose errors, prevent abuse, and improve the service.
- To answer your support requests and send service notices about the app.
We do not sell your data, we do not share it with advertisers, and we do not use it for advertising or profiling.
AI processing
Scout produces its reviews with large language models. To do that, the pull request diff, the relevant surrounding source files, and the content of the linked Jira issue are sent to our model provider, which acts as our sub-processor under a written agreement.
- Content is sent only when a review runs, and only the parts needed for that review.
- Our agreement with the provider prohibits using your content to train their models.
- Content is not retained by the provider beyond the short window needed to serve the request and meet its abuse-monitoring obligations.
- Reviews are advisory. A human reviewer remains responsible for what merges.
If your organization needs the current provider named in writing, or needs a data-processing addendum on file, contact privacy@scout.app.
Storage and retention
- Account, GitHub and Jira connection records — kept for as long as your account exists and the integration is connected.
- Forge installation records — kept for as long as the app remains installed on the site.
- Jira issue and repository content — processed in transit to produce a review. It is not written to our database.
- Operational logs — kept for a limited period for troubleshooting and security, then discarded on a rolling basis.
Data is stored on infrastructure operated by our hosting provider, and the Forge app runs on Atlassian’s own Forge infrastructure.
Security
- All traffic runs over HTTPS/TLS, between the Forge app, our backend, Atlassian and GitHub.
- The Forge app requests the minimum Jira scope it needs —
read:jira-work— and holds no write access to your Jira data. - Each Jira installation gets its own unguessable web-trigger URL, scoped to that installation, and our backend verifies the site before serving a request.
- The GitHub App only sees the repositories you selected, and you can change that selection or revoke it at any time from GitHub.
- Credentials and signing secrets are held server-side and are never exposed to the browser.
- Access to production systems is limited to staff who need it.
No system is perfectly secure. If you believe you have found a vulnerability, please report it to security@scout.app and give us a reasonable window to fix it before public disclosure.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent. Where the GDPR applies, our legal bases are the performance of our contract with you, and our legitimate interest in operating and securing the service.
To exercise any of these rights, email privacy@scout.app. We answer within 30 days. You also have the right to complain to your local data protection authority.
Deletion and uninstall
You can remove your data yourself, at any time
- Uninstall the Forge app from your Jira site — we delete that site's installation record, including its web-trigger URL.
- Disconnect Jira from the Scout dashboard — we delete the stored Jira connection record.
- Uninstall the Scout GitHub App from your GitHub account or organization — we delete the stored installation and repository selection.
To delete your Scout account and everything associated with it, email privacy@scout.app. We complete deletion within 30 days, except where we are required to retain something by law.
International transfers
Scout is operated from India and uses providers that may process data in other countries, including the United States and the European Union. Where data leaves your region, we rely on appropriate safeguards — such as the European Commission’s Standard Contractual Clauses — so it stays protected consistently with this policy.
Children’s privacy
Scout is a business tool intended for use by organizations. It is not directed at children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact us and we will delete it.
Changes to this policy
We may update this policy as the product changes. The “Last updated” date at the top of this page always reflects the current version. For material changes — a new category of data, a new sub-processor, a new purpose — we will give notice in the dashboard or by email before the change takes effect.
Contact us
Scout — privacy contact
Questions about this policy, or about what we hold on you: privacy@scout.app
General help with the app: support@scout.app — or see the support page.
Security reports: security@scout.app