On 17 August 2026, Atlassian begins using customer data from Jira, Confluence, and Jira Service Management by default to train its AI, including Rovo and Rovo Dev. The change reaches roughly 300'000 organisations. If you run your project work in Atlassian Cloud, it is worth understanding what the change does, and worth asking whether the underlying model is the one you want for your team's data.
What actually changes on 17 August
Atlassian collects two categories of data. Metadata covers things like story points, sprint dates, readability scores, and similarity measures. In-app data is the actual content: Jira issue titles, descriptions, and comments, plus Confluence page titles and bodies, and custom workflow and status names.
Your ability to say no depends on your plan. On Free, Standard, and Premium, metadata contribution is mandatory and cannot be switched off, though you can toggle off in-app content. Only on the Enterprise tier is collection off by default for both categories. Collected data can be retained for up to seven years, and admins find the controls under Atlassian Administration, Security, Data contribution.
To be fair to Atlassian: this is not a breach, and the company describes real safeguards. Content is de-identified and aggregated before it enters a training pipeline, and it says customer data is not handed to third-party model providers for their own training. Reasonable teams will read those safeguards differently depending on what sits in their tickets and pages.
The deeper issue is the model, not the toggle
Here is the pattern worth noticing. When your work tools run in someone else's cloud, "how is our data used" is never settled. It is a policy that can change, on a schedule you do not control, with defaults that can flip from off to on. You opt out today. Next year there is a new setting, a new tier boundary, a new retention window. The homework is never finished.
A service desk makes this concrete. The free-text body of a ticket can hold a password reset, an HR case, a security incident, a vendor dispute. None of it was written with a training pipeline in mind. Deciding, page by page, what is safe to contribute is work most teams should not have to do at all.
How VNCproject approaches it
VNCproject is the project and task management module of VNClagoon, the open-source sovereign workplace. It runs on your own infrastructure, on-premises or in a European cloud. Your boards, issues, comments, and linked documents stay inside your perimeter.
That changes the question entirely. There is no data-contribution setting to find, because there is no contribution. There is no retention window to track, because your data was never sent anywhere to begin with. When you use AI in VNCproject, VNClagoon AI runs locally: task generation, summaries, and search happen on your own hardware, and nothing leaves the building. Because the code is open source, your security team can verify exactly what the platform does rather than take a policy page on trust.
Moving is not all-or-nothing
You do not have to migrate everything in a weekend. Run VNCproject alongside what you have, bring your boards and workflows across, and expand into VNCmail, VNCtalk, and VNCchannels when the time is right. Teams tired of a rising per-seat invoice tend to start here and grow the footprint from there.
The question to keep
Atlassian's change is a useful prompt, whatever you decide about the toggle. Ask it of every tool your team relies on: whose infrastructure is our work sitting on, and who decides what happens to it? With VNCproject, the answer stays with you.
The Sovereign Workplace.
Book a demo · See VNCproject live
Sources
- Atlassian, "Data practices built for responsible AI" (Atlassian Trust Center)
- Seibert Group, "Atlassian Data Privacy: The 2026 AI Training Policy Change"
- GitLab, "Atlassian will train on your data: opt out with GitLab"
- K-AI, "Atlassian Will Train Its AI on Your Confluence Data: What Enterprise Leaders Must Decide Before August 17"
Policy details reflect Atlassian's published data-contribution terms effective 17 August 2026. Verify current settings in Atlassian Administration, Security, Data contribution before acting.