See what Scroll Support Hub can read and write in Jira, what it stores, and what it records on each request it creates.
The app is built on Atlassian Forge, so it runs inside Atlassian's infrastructure under Atlassian's security and data residency controls. Your requests, comments, and attachments never pass through servers run by K15t.
What the App Can Access in Jira
|
Permission |
What it is used for |
|---|---|
|
Read and write service management requests |
List a customer's requests, open one, post their replies, and create new requests. |
|
Act on behalf of a customer |
Show each person only their own requests, and attribute their replies to them instead of to the app. |
|
Read and write Jira work items |
Read request fields and attachments, and mark each widget request so you can find it with JQL. |
|
Manage project and Jira configuration |
Read the options of custom fields, so dropdowns on the request form show the right choices. |
|
Read a user's email address |
Match a signed-in customer to the requests they sent before they signed in. |
|
App storage |
Store the list of connected sites. |
Because the app acts on behalf of the signed-in customer, Jira applies the same permissions as in the portal. A customer can only see a request in the widget if they can also see it in Jira Service Management (JSM).
What the App Stores
The app stores only the list of connected sites. For each site, this is the address, the Connection ID, the service project, and the default request type.
It does not store requests, comments, attachments, customer names, email addresses, or sessions. All of that stays in JSM, and the app reads it live each time it needs it.
Only Approved Websites Can Show the Widget
The widget only works on a website you have added to Connected sites. Two independent checks enforce this:
-
The widget tells the browser which single website may display it. The browser blocks the widget on any other website.
-
Every call the widget makes is checked against the approved list before Jira answers.
These checks stop someone from copying your widget onto their own website and using your service project. You can only add addresses that use https://. The list is checked live, so removing a site takes effect at once.
Attachments are downloaded as the signed-in customer, and only from the request they belong to. Nobody can use a link to reach a file from someone else's request. Uploads are limited to an allow-list of file types. For the list, see Attach Files to a Request.
What Is Recorded on Each Request
Every request created through the widget carries two markers.
The first is a set of properties you can search with JQL: the website the request came from, its Connection ID, and whether the visitor was signed in. See Find Widget Requests in Jira With JQL.
The second is an internal comment that your agents can see and the customer cannot. It names the website the request came from. If the visitor searched the help center first, the comment also lists what they searched for and which articles the widget showed them.
The comment gives agents useful context. It also means your support team can see what the visitor typed into the search box. Tell your team about the comment, and consider it when you write your own privacy notice.
Cookies and Sessions
The widget sets two cookies, both on the app's own address instead of on your help center, so they do not interfere with a consent tool you already run there. Neither cookie is used for advertising, tracking across websites, or building a profile. A visitor who never signs in gets neither of them.
|
Name |
Purpose |
Lifetime |
Set when |
|---|---|---|---|
|
|
Holds the signed-in session, so the widget knows whose requests to show. Scripts on the page cannot read it, and it is only sent over HTTPS. |
24 hours |
A visitor signs in |
A signed-in session lasts 24 hours. Signing out clears it from that browser. Both cookies are strictly necessary for a feature the visitor asked for, so in most jurisdictions they do not need consent. Check this with your own legal advisers.
Related Articles