7 Years Is Atlassian's Opt-Out Fine Print

Monday the new data terms go live for Jira and Confluence. OpenAI is already on the sub-processor list.

Share

Introduction

If your team uses Jira or Confluence: opt out of Atlassian's data policy this week, and the company says your data clears out in 30 to 90 days. Its own support documentation says the aggregated leftovers, built from your search queries and Rovo Chat prompts, can stick around for years longer than that. That policy goes contractually live Monday: the Customer Agreement itself carries the line "Effective starting: August 17, 2026." Neither the opt-out nor the deadline touches what Atlassian discloses elsewhere: its sub-processors list, effective May 15, names OpenAI, L.L.C. as an authorized processor of customer data across every cloud product running Atlassian Intelligence or Rovo. Location of processing: USA.

OpenAI Was Already on Atlassian's List

That table is a ceiling, not a manifest. When a customer flagged an apparent conflict between it and Atlassian's AI transparency page, an Atlassian solutions engineer answered in a community thread that the sub-processors page lists "the categories of data a vendor may process," while the transparency page "accurately describes what prompt and context data is actually sent to third-party LLMs." The customer said Atlassian's support channel wouldn't answer him directly.

The same engineer itemized what does get sent when Rovo pulls context to answer a request: prompts and responses, "relevant context" that may include snippets from Jira issues and Confluence pages, uploaded file contents, and "minimal metadata needed to fulfill the request (e.g., user permissions, document titles)." Atlassian's AI transparency page says the same, listing Confluence pages and Jira work items among what Rovo Chat processes as context.

The data contribution FAQ draws a real line: metadata and in-app data collected under Monday's policy is not shared with those providers "for them to use to train or improve their services," and Atlassian says its LLM partners operate under "strict zero data retention" agreements. So if a version of this story reaches you claiming Atlassian trains OpenAI's models on your Jira tickets, Atlassian's own documentation denies it. What the documentation supports is narrower and harder to check: your team's ticket and page text reaching a US-based sub-processor on retention terms no customer can verify.

What Monday Actually Decides

Metadata contribution is where the tiers split. Atlassian's head of product communications, Arseny Tseytlin, told The Register in April: "If an Atlassian customer's highest active plan is Free, Standard, or Premium, metadata contribution is always on, and they are not able to opt out." Enterprise is the only tier with that toggle, and the only tier Atlassian doesn't publish a price for.

In-app data, meaning the actual page text and ticket descriptions, can be switched off on any tier including Free. Customer-managed encryption keys, Government Cloud, Isolated Cloud, and HIPAA configurations sit outside data contribution entirely. The rollout ran four months, settings appearing April 16 and finishing May 19, with a 90-day review window. Monday isn't a door closing either: the FAQ says settings can change "at any time," though the support docs add that metadata contribution switches itself back on if an organization downgrades out of Enterprise.

Seven Years of "Common Patterns"

"Metadata" is doing heavy lifting as a word. I'd have guessed timestamps and click counts. Atlassian's support documentation defines "content attributes" to include a "readability score or the complexity of Confluence page content" and a "semantic similarity score" measuring how similar two Confluence pages are. The other half, "common patterns," comes from search queries and results, prompts and responses in Rovo Chat, and configuration items customers define.

Common patterns feed the aggregated pool, and Atlassian's support documentation puts a number on how long that pool sticks around: "Data that is de-identified and aggregated at a customer level such that it is no longer associated with individual customers (including common patterns), may be retained for up to seven years." Tseytlin's rationale, to The Register: data de-identified and aggregated at a customer level "enables us to make more meaningful observations over longer periods of time."

Who Benefits

Atlassian's fiscal 2026 results, reported August 6, put revenue at $6.572 billion, up 26%, and remaining performance obligations at $4.817 billion, up 44%. The net loss narrowed roughly 79% to $54 million, and operating income came in positive at $10.4 million. Mike Cannon-Brookes put the strategy in the earnings release: "In the AI era, context is the edge but it's hard to build and can't be hired. Thanks to 25 years of connecting teams, customers get one of the best context graphs for orchestrating agentic workflows."

The shareholder letter sizes that graph at "over 200 billion objects and connections." Contributed metadata is one of its inputs, and the only tier that can decline is the one with no list price.

Cannon-Brookes' own exposure runs bigger than the headline number. In the earnings release he announced an intention to enter a Rule 10b5-1 plan to buy up to $250 million of stock. He hasn't filed a Form 4 yet. He holds roughly 20% of the company, per the Financial Times; the Sydney Morning Herald put his family trust's 47.3 million shares at $5.2 billion before the August 6 release and roughly $7 billion hours after. That same shareholder letter reports Atlassian repurchased 19.1 million shares for $1.8 billion in FY26, so the $250 million plan is a smaller signal than it reads as. Neither he nor Atlassian has connected the plan to the data policy.

OpenAI's side is simpler. The Rovo traffic it serves is enterprise usage on its books, and it markets its own Atlassian connector pulling Jira and Confluence data the other direction into ChatGPT.

If You Want the Off Switch, Call Sales

A team paying per seat on Premium has exactly as much control over cross-customer metadata use as one on Free, which is none. The toggle exists and works, and it's gated to the plan you have to call a salesperson to buy.

The obvious defense is that every SaaS company does some version of this, and mostly they do, which is why Monday's checkbox is the smaller half of the story. Admins are fighting this week over the metadata pool, the one Atlassian controls end to end and says it will retrain models to remove you from, and not over the pool carrying real ticket text and uploaded files to a named US sub-processor, on contracts only Atlassian can read and never listed on the settings page.

The Bottom Line

Monday settles which organizations get a choice about the metadata pool. Free, Standard, and Premium organizations lose an argument they were never going to win; Enterprise keeps a switch covering one of the two flows, and the OpenAI row on the sub-processor table stays put either way.

Here's what I'd want answered before Monday: what would Atlassian have to publish for anyone outside the company to confirm that zero data retention means what it says? Right now the answer is a page describing its own contract terms. When one customer pushed on the gap between two of those pages, it took a solutions engineer on a forum to explain it.