Skip to content
Scout

Legal

Privacy Policy

This policy explains what Scout does with information when you install or use it with your Atlassian Cloud site and your GitHub repositories — what is read, what is stored, who it is shared with, and how to get it deleted. Installing or using Scout means you accept the practices described here.
Last updated
September 10, 2026
Applies to
Scout for Jira Cloud
Jira scopes
read:jira-work
Data controller
Scout
On this page
01

Who this covers

Scout is an automated code-review agent. It reads a pull request, the repository around it, and the Jira issue linked to it, and publishes a review back to the pull request. It reaches Jira through an Atlassian Forge app installed on your site (app id ari:cloud:ecosystem::app/3d369f25-f2bc-42be-9b55-239abfe7a143), and reaches your code through a GitHub App you install on the repositories you choose.

This policy covers the Forge app, the Scout web dashboard, and the Scout backend service that connects them. It does not cover Atlassian, GitHub, or any other third-party service you use — their own privacy policies govern those.

For the purposes of the GDPR, Scout is the data controller for account data, and a data processor acting on your instructions for the Jira and repository content it reads on your behalf.

02

What we collect

2.1 Account data

You sign in to the Scout dashboard with GitHub. From that sign-in we store your name, email address, GitHub user id, GitHub username, and avatar URL.

2.2 GitHub installation data

When you install the Scout GitHub App we store the installation id, the account it was installed on and its type (user or organization), whether you selected all repositories or a subset, and the names of the selected repositories.

2.3 Jira connection data

When you connect Jira from the dashboard via Atlassian OAuth 2.0 (3LO) we store your Atlassian account id, the account email address, and the id, name and URL of the site you selected.

2.4 Forge installation data

When the Forge app is installed on a Jira site, it registers that installation with our backend. We store the site base URL (for example your-team.atlassian.net), the Forge installation identifier, and the unique web-trigger URL Forge generates for that installation. That URL is how our backend asks your site for issue data.

2.5 Content read on demand

To produce a review, Scout reads — at the moment of the review, through official Atlassian and GitHub APIs:

  • Jira issue content — issue key, summary, description, status, issue type, priority, assignee, and created/updated timestamps for the issue linked to the pull request, or for issues in a project you name.
  • Repository content — the pull request diff, its title and description, and the surrounding source files needed to understand the change and what it can affect.

This content is processed to generate the review and returned to the requester. We do not build a permanent copy of your Jira projects or your source code.

2.6 Operational logs

The Atlassian Forge platform and our backend record standard operational logs — timestamps, request outcomes, and error messages — which we use to run the service and diagnose faults. Logs may incidentally contain identifiers such as a site URL or an issue key.

2.7 What we never collect

  • Atlassian or GitHub passwords — authentication is delegated to OAuth and to the Forge platform.
  • Payment card details.
  • Analytics, advertising, or cross-site tracking identifiers.
03

How we use it

  • To deliver the product's core function: reading the pull request and the linked Jira issue, and publishing a review.
  • To route each request to the correct Atlassian installation and the correct GitHub repository.
  • To authenticate you and keep your dashboard session and connection status accurate.
  • To monitor reliability, diagnose errors, prevent abuse, and improve the service.
  • To answer your support requests and send service notices about the app.

We do not sell your data, we do not share it with advertisers, and we do not use it for advertising or profiling.

04

AI processing

Scout produces its reviews with large language models. To do that, the pull request diff, the relevant surrounding source files, and the content of the linked Jira issue are sent to our model provider, which acts as our sub-processor under a written agreement.

  • Content is sent only when a review runs, and only the parts needed for that review.
  • Our agreement with the provider prohibits using your content to train their models.
  • Content is not retained by the provider beyond the short window needed to serve the request and meet its abuse-monitoring obligations.
  • Reviews are advisory. A human reviewer remains responsible for what merges.

If your organization needs the current provider named in writing, or needs a data-processing addendum on file, contact privacy@scout.app.

05

Storage and retention

  • Account, GitHub and Jira connection records — kept for as long as your account exists and the integration is connected.
  • Forge installation records — kept for as long as the app remains installed on the site.
  • Jira issue and repository content — processed in transit to produce a review. It is not written to our database.
  • Operational logs — kept for a limited period for troubleshooting and security, then discarded on a rolling basis.

Data is stored on infrastructure operated by our hosting provider, and the Forge app runs on Atlassian’s own Forge infrastructure.

06

Sharing and sub-processors

We share information only in these limited circumstances:

  • Atlassian — the Forge app runs on Atlassian’s platform and calls Atlassian APIs in order to function.
  • GitHub — we read pull requests and publish reviews through the GitHub API using the installation you authorized.
  • Our model provider — as described in section 4.
  • Infrastructure providers — hosting and database services that run the Scout backend, under contract and bound to confidentiality.
  • Legal requirements — where required by law, regulation, or valid legal process.
  • At your direction — where you configure Scout to send output to a destination you control.

We do not sell personal information, and we do not share it for cross-context behavioural advertising.

07

Security

  • All traffic runs over HTTPS/TLS, between the Forge app, our backend, Atlassian and GitHub.
  • The Forge app requests the minimum Jira scope it needs — read:jira-work — and holds no write access to your Jira data.
  • Each Jira installation gets its own unguessable web-trigger URL, scoped to that installation, and our backend verifies the site before serving a request.
  • The GitHub App only sees the repositories you selected, and you can change that selection or revoke it at any time from GitHub.
  • Credentials and signing secrets are held server-side and are never exposed to the browser.
  • Access to production systems is limited to staff who need it.

No system is perfectly secure. If you believe you have found a vulnerability, please report it to security@scout.app and give us a reasonable window to fix it before public disclosure.

08

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent. Where the GDPR applies, our legal bases are the performance of our contract with you, and our legitimate interest in operating and securing the service.

To exercise any of these rights, email privacy@scout.app. We answer within 30 days. You also have the right to complain to your local data protection authority.

09

Deletion and uninstall

You can remove your data yourself, at any time

  • Uninstall the Forge app from your Jira site — we delete that site's installation record, including its web-trigger URL.
  • Disconnect Jira from the Scout dashboard — we delete the stored Jira connection record.
  • Uninstall the Scout GitHub App from your GitHub account or organization — we delete the stored installation and repository selection.

To delete your Scout account and everything associated with it, email privacy@scout.app. We complete deletion within 30 days, except where we are required to retain something by law.

10

International transfers

Scout is operated from India and uses providers that may process data in other countries, including the United States and the European Union. Where data leaves your region, we rely on appropriate safeguards — such as the European Commission’s Standard Contractual Clauses — so it stays protected consistently with this policy.

11

Children’s privacy

Scout is a business tool intended for use by organizations. It is not directed at children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact us and we will delete it.

12

Changes to this policy

We may update this policy as the product changes. The “Last updated” date at the top of this page always reflects the current version. For material changes — a new category of data, a new sub-processor, a new purpose — we will give notice in the dashboard or by email before the change takes effect.

13

Contact us

Scout — privacy contact

Questions about this policy, or about what we hold on you: privacy@scout.app

General help with the app: support@scout.app — or see the support page.

Security reports: security@scout.app