Skip to content

Data and Privacy

Script Toolkit is a Forge app: it runs on Atlassian's infrastructure, and everything it stores is kept in Atlassian's Forge storage for your site. Yamuno runs no servers for it and receives none of your data.

What it stores

Data Where Kept until
Scripts: name, code, settings, who created and last edited them Forge storage You delete the script
Logs: what scripts print, and each run's result and duration Forge storage The retention you set (1–14 days), or sooner when log storage is full
Settings, limits, tool access and daily usage counters Forge storage You change them
Secret values Forge's encrypted secret storage, write-only from the UI You delete the secret
Secret names, and who last set each Forge storage You delete the secret

Script Toolkit doesn't copy your Jira data. Scripts read and change Jira through its REST API; anything a script logs is kept as part of its logs for the retention period, so avoid logging personal or sensitive data.

Personal data

The only personal data stored is Atlassian account ids: who created and last edited each script, and who last set each secret. Once a week the app reports these to Atlassian's personal data reporting API, and replaces the ids of closed accounts with an anonymous marker.

Where scripts run

Scripts Run Call Jira as
Script Console, fragments, gadgets In the viewer's browser The viewer
Web triggers, scheduled jobs, scripted fields, workflow extensions On Forge, in an isolated sandbox inside the app The app; read only unless the script allows writes

What can leave your site

Only what your scripts send. Nothing is sent by default:

  • Backend scripts can call outside services with fetch only if Settings → Backend scripts → Outbound requests allows it: off, listed hosts only, or any public https host. Private and internal addresses are always refused.
  • Fragments and gadgets run in the viewer's browser and can call outside services from there, like any web page the viewer opens.

Because scripts may call outside services, the app declares outbound access in its Forge manifest. That's why it isn't in Atlassian's "Runs on Atlassian" program.

Permissions it asks for

Scope Why
read:jira-work, write:jira-work Scripts and tools read and change work items
read:jira-user Show who saved a script; scripts look up users
manage:jira-configuration, manage:jira-project Check that the person is a Jira admin, and let scripts manage configuration and projects when asked
storage:app Keep scripts, logs and settings in Forge storage

Backend scripts are read only unless an admin turns on writes for that script. Only Jira admins can create or change scripts; Tools run with each person's own permissions.

Uninstalling

Uninstalling the app deletes its Forge storage (scripts, logs, settings and secrets) from your site.