Atlassian, the powerhouse behind Jira and Confluence, just flipped a switch on its data policy. Starting August 17, 2026, the company will scoop up customer metadata and in-app content from its cloud products to train AI features like Rovo and Rovo Dev. This shift marks a sharp turn from earlier promises. No more vows against using customer data for model training. Now, it’s fair game—for most users, anyway.
The rollout creeps in early. Settings appear in Atlassian Administration from April 16, 2026, giving admins until May 19 to tweak before defaults lock in. Affected tools? Jira, Confluence, Jira Service Management, plus platform apps such as Rovo, Home, and Analytics. That’s the daily grind of roughly 300,000 organizations worldwide.
Break it down: two data buckets. Metadata captures signals like readability scores on Confluence pages, task classifications in Jira, semantic similarity between documents, story points, sprint end dates, and SLA metrics. In-app data goes deeper—page titles and bodies in Confluence, issue titles, descriptions, comments in Jira, even custom emoji names, status labels, and workflow titles. All get de-identified first. Names, emails stripped. Then aggregated at the customer level. Rare, unique patterns? Omitted to dodge re-identification risks.
But here’s the kicker. Defaults hinge on your highest plan. Free and Standard? Both metadata and in-app collection switched on—no off ramp for metadata. Premium keeps metadata mandatory but starts in-app off. Enterprise? Both off by default, with full opt-out power, including metadata. Exclusions shield some: customer-managed encryption keys, Government Cloud, Isolated Cloud, HIPAA-bound setups, certain government or financial services. Terminate before August 17? You’re out clean.
Atlassian’s line: this powers real gains. Better search relevance. Smarter summaries. Template suggestions that hit. Agentic workflows that anticipate next steps. As Atlassian Trust Center states, “By learning from richer, more diverse customer data and usage patterns, we can deliver enhanced AI capabilities.” Arseny Tseytlin, head of product communications, told The Register, “Retaining this data, which has been de-identified and aggregated at a customer level and is common across customers, enables us to make more meaningful observations over longer periods of time.” Data sticks around up to seven years for those insights. Opt out? In-app data vanishes from datasets in 30 days; models retrain in 90.
Not everyone’s buying it. Free and Standard users—often startups, small teams—face mandatory metadata feeds. That’s project skeletons, velocity patterns, workflow quirks exposed. Even de-identified, it sketches competitive edges. Premium folks dodge in-app but not metadata. Enterprise pays for the privilege of saying no. Critics call it a paywall on privacy.
X lights up with gripes. One user warns, “Atlassian just silently opted everyone into default data collection to train their AI models. If you use Jira or Confluence, check your admin settings immediately before your proprietary code becomes training data.” Another: “Your project discussions, customer data, and competitive strategies are now feeding their AI models unless you actively opt out.” Hacker News threads the Let’s Data Science piece, dissecting risks from seven-year holds to regulatory heat.
gHacks spells out the tier traps plainly. Free and Standard locked into metadata; no escape. Enterprise gets the keys. OraCore urges audits now: “Teams should check organization settings… as new defaults will apply regardless.” Industry echoes? Microsoft, Salesforce, Google Workspace tap similar veins, but with variances in consent and controls.
So, what’s the play? Admins, log into Atlassian Administration. Organization level only—no per-user tweaks. Toggle in-app where you can. Enterprise? Opt everything out. But metadata mandates linger for lower tiers. Delete sensitive content? It purges in 30 days post-change. Models forget in 90.
This isn’t isolated. SaaS giants chase AI edges through user data. Atlassian bets aggregation and de-identification assuage fears. Benefits tempt: intuitive apps, workflow magic. Yet trust frays when defaults favor the house. Small outfits subsidize Enterprise polish via data drops. Privacy as premium perk.
Regulators watch. GDPR, emerging AI acts demand transparency. Seven-year retention? A flashpoint. De-identification holds? Only as strong as the next breach. Customers push back via X, forums, contracts. Some eye self-hosted Data Center escapes—AI-free zones.
Atlassian insists safeguards tighten: access limits, monitoring, low-frequency filters. “We designed this change with your security and privacy in mind,” per their site. But opt-out asymmetry stings. Free users fuel the fire. Paying ones fan it optionally.
Watch the backlash build. Webinars loom—April 28 details the shift. Admins prep. Teams audit tickets, pages. The AI arms race claims another front: your daily logs. Consent buried in tiers. Data’s new currency. Who pays the toll?


WebProNews is an iEntry Publication