Atlassian Announces AI Training Data Collection—Free and Paid Users Can't Opt Out
docAtlassian announced on April 18-19, 2026 that starting August 17, 2026, it will collect customer metadata and in-app content from Jira, Confluence and other cloud products by default to train AI models (Rovo, Rovo Dev). Affecting roughly 300,000 global customers, the policy creates a controversial two-tier privacy system where only Enterprise users can opt out.
Atlassian Announces AI Training Data Collection—Free and Paid Users Can't Opt Out
What Happened
On April 18-19, 2026, Atlassian made a major announcement that sent shockwaves through the developer and IT community. Starting August 17, 2026, the company will begin collecting customer metadata and in-app content from its flagship cloud products—including Jira, Confluence, and other cloud services—and use it by default to train its AI models, specifically Rovo and Rovo Dev.
The scope of this change is enormous. Approximately 300,000 customers worldwide use Atlassian's cloud products, and virtually all of them will be affected.
The Two-Tier Privacy System
At the heart of this announcement is what can only be described as a two-tier privacy system. The key distinction comes down to pricing tier:
- Enterprise tier customers can opt out of data collection entirely
- Free, Standard, and Premium tier users cannot opt out of metadata collection
This creates a deeply problematic situation. Users on free or lower-tier paid plans—who are often individuals, small teams, startups, and independent developers—have no means of preventing their data from being used to train Atlassian's AI products. Only large enterprises with the budget for Enterprise tier subscriptions can maintain control over their data.
This structure inverts the normal logic of privacy protection. Instead of privacy being a baseline right that costs money to provide, Atlassian has made it so that data sovereignty is a premium feature that only well-funded organizations can afford.
What Data Is Being Collected
Atlassian has indicated that the following types of data will be collected:
- Issue and page body text from Jira and Confluence
- File attachments
- User behavior logs
- Metadata associated with content and user activity
The exact boundaries of what will and will not be collected remain somewhat unclear. Atlassian's published documentation does not provide a complete picture of the data collection scope, and this lack of transparency has been a significant point of criticism.
Products Affected
The data collection applies to Atlassian's core cloud products:
- Jira — project management and issue tracking
- Confluence — team knowledge sharing and documentation
- Other cloud products — including AI services Rovo and Rovo Dev
Legal and Ethical Concerns
Informed Consent Issues
Modern privacy regulations—including Europe's GDPR and Japan's Personal Information Protection Act—typically require explicit, informed consent from users before their data can be used for secondary purposes like AI training. Atlassian's approach of default collection, where users are automatically enrolled unless they take action to opt out, raises serious questions about compliance.
Default opt-in models have repeatedly faced regulatory scrutiny. The European Data Protection Board has consistently held that pre-ticked boxes and default enrollments do not constitute valid consent under GDPR.
Previous Industry Precedents
Atlassian's parent company Adobe faced significant legal consequences in multiple countries in 2024 when it was discovered that the company had been using customer data for AI training purposes without adequate disclosure or consent. Atlassian appears to be following a similar playbook, which raises the question of whether it will face comparable regulatory action.
The EU AI Act, which came into full force in 2025, imposes additional requirements on companies using user data to train AI systems, and default data collection practices may run afoul of these new rules.
How Enterprise Users Can Opt Out
For Enterprise tier customers who wish to opt out of data collection, Atlassian has outlined the following process:
- Log in to the Admin Console
- Navigate to Data Management settings
- Disable the AI training data use option
- Data collection will cease after the change is applied
However, the process is not fully documented in publicly available materials, and some administrators have reported that the opt-out mechanism is difficult to locate or understand. This complexity may effectively prevent many users from exercising their opt-out rights even when they are technically eligible.
Impact on the Broader Industry
A Dangerous Precedent
Atlassian's move could have ripple effects throughout the SaaS industry. If default data collection for AI training proves profitable and legally defensible for Atlassian, other companies may adopt similar practices. The result could be a systematic erosion of user privacy across the cloud software ecosystem.
Small and medium-sized businesses, who are the most dependent on affordable SaaS tools, would bear the brunt of this trend. They lack the resources to migrate to self-hosted alternatives or pay premium prices for privacy-respecting tiers.
Competitive Opportunities
On the other hand, Atlassian's competitors who position themselves as privacy-first alternatives stand to gain. Companies offering Jira and Confluence alternatives—or self-hosted versions of similar tools—have already reported increased interest since the announcement.
What Users Can Do
Options for Avoiding Data Collection
At present, the viable options for avoiding data collection are limited:
- Upgrade to Enterprise — often not financially feasible for small teams
- Migrate to competing services — evaluate alternative tools with comparable functionality
- Switch to self-hosted versions — Jira and Confluence Data Center (server versions) are reportedly not subject to the same data collection policies
Data Protection Measures
Regardless of platform choice, users should consider:
- Encrypting sensitive data before uploading to any cloud platform
- Regularly auditing application permissions and removing unnecessary access grants
- Evaluating privacy policies and data handling practices when selecting tools
Conclusion
Atlassian's AI training data collection policy represents a fundamental challenge to how we think about privacy in the cloud era. The two-tier system that reserves data sovereignty for enterprise customers while subjecting everyone else to default collection inverts the principles of democratic privacy rights.
Users should take the time between now and August 17, 2026 to understand how their data will be used and to make informed decisions about their tool choices. The clock is ticking—but there is still time to act.