Monitored company
Trello
clause.watch tracks 2 legal documents published by Trello, re-reading each one every six hours. Below is what each document covers, in plain English.
Privacy Policy
Atlassian Privacy Policy Overview
Effective date: August 17, 2026
Applies to: Atlassian products, websites, cloud/software services, support channels, forums, Marketplace, and related services.
> This is a plain-English summary, not legal advice. The policy is broad and should be read with Atlassian’s Cookies & Tracking Notice, customer Data Processing Addendum, Marketplace terms, and regional disclosures.
1. Data Collection & Usage
Information collected
Atlassian collects information:
- Directly from you: name, email, profile photo, job title, organization, preferences, billing and payment details, support requests, screenshots, feedback, survey responses, and other submitted content.
- Automatically: features used, actions performed, files and attachments (including filenames and sizes), search activity, collaborations and communications, links clicked, device and browser details, IP address, referring/exit URLs, crash data, device identifiers, approximate location, cookies, pixels, and similar tracking data.
- From others: invitations, administrators, employers, Atlassian affiliates, partners, social-media platforms, public databases, and business-information providers.
Main purposes
The information may be used to:
- Provide, authenticate, personalize, maintain, and support the Services.
- Process payments and manage subscriptions.
- Develop new features and improve security, performance, integrations, recommendations, and user experience.
- Send transactional and marketing communications, including targeted advertising.
- Detect fraud, abuse, security incidents, and policy violations.
- Comply with law, defend legal rights, conduct audits, and handle mergers or acquisitions.
- Create aggregated or de-identified data for product development and marketing.
Important scope issue: For content submitted through Atlassian products, Atlassian generally says it acts as a processor/service provider for the customer organization—for example, your employer. In that situation, the organization, not Atlassian, controls the account and determines many data practices. You may need to exercise rights through that organization.
2. User Rights and Choices
Depending on location, users may be able to:
- Access and obtain a copy of their information.
- Correct or update inaccurate information.
- Delete information or an account.
- Restrict or object to processing.
- Withdraw consent.
- Receive data in a portable, machine-readable format or request transfer to another provider.
- Opt out of promotional communications.
- Opt out of targeted advertising and certain U.S. “sales” or “sharing.”
- Appeal a denied U.S. privacy request.
- Complain to a data-protection authority, particularly in the EEA or UK.
These rights have exceptions—for example, where deletion would conflict with legal retention duties or reveal another person’s information. Data shared with third-party apps generally must be deleted or restricted by contacting those providers directly.
3. Third-Party Sharing
Atlassian may disclose information to:
- Hosting, storage, backup, payment, analytics, security, support, development, and marketing providers.
- Atlassian partners, consultants, resellers, event sponsors, and affiliates.
- Third-party apps and services that users or administrators connect, including Marketplace apps.
- Advertising providers for targeted advertising.
- Government authorities or law enforcement when legally required or reasonably necessary to protect people, systems, or rights.
- A buyer or successor during a merger, sale, financing, reorganization, or acquisition.
Connected third-party services operate under their own policies. Installing or linking an app can give it access to account information and potentially other data, depending on permissions.
Information posted in public forums, blogs, wikis, issue trackers, or communities may be viewed, copied, and retained by the public even after account termination.
4. AI/ML Training
Yes—AI and machine-learning use is expressly contemplated.
The policy states that Atlassian may use information for development, training, or fine-tuning of AI/ML models, particularly in connection with customer support. It also uses generative AI for pricing, billing, licensing, support responses, security monitoring, fraud detection, and other functions.
For EEA/UK users, the policy specifically lists developing and improving Services—including machine-learning and AI model training—as a processing purpose. Atlassian also describes using de-identified and aggregated content and usage information for product development. However, the policy is not a blanket promise that all user content is excluded from AI-related processing. Employer-managed users should check the customer agreement and applicable product data-contribution settings.
5. Key User Responsibilities and Risks
- Do not use the Services if you disagree with the policy.
- Exercise caution before submitting confidential, sensitive, or personal information in public forums or support materials.
- Review permissions before connecting third-party applications.
- If your account uses an employer or organization domain, administrators and other users may gain access to profile details, content, and past account use.
- You are responsible for understanding your employer’s privacy practices where it controls the account.
- Services are not intended for children under 16.
- Marketing opt-out does not stop transactional messages or generic advertising.
- International transfers may send information to countries with different privacy protections.
6. Liability and Disputes
This privacy policy provides no detailed compensation scheme or broad guarantee of security. Atlassian states that it uses industry-standard safeguards but cannot guarantee absolute security because no system or Internet transmission is impenetrable.
The policy permits disclosures for legal compliance, enforcement, emergencies, and business transfers. Privacy complaints should generally be directed to privacy@atlassian.com. EEA/UK users may contact a supervisory authority. For certain EU/UK/Swiss transfers under the Data Privacy Framework, unresolved complaints may proceed through TRUSTe and, in limited circumstances, binding arbitration. Other contract terms—not this policy—may contain additional liability limits, governing-law rules, arbitration provisions, or dispute procedures.
7. Policy Changes
Atlassian may amend the policy by posting a new version online. Significant changes may also receive a prominent website/login notice or email to users subscribed to legal updates. Continued use is not expressly described as acceptance, but users who disagree must stop using the Services, deactivate accounts, or request deletion. Prior versions are maintained in an archive.
Terms
Atlassian Customer Agreement: Key User Implications
> Scope note: This is primarily a commercial customer agreement, not a standalone privacy policy. Important privacy details—such as specific data fields, retention, international transfers, and individual data rights—are incorporated by reference through the Data Processing Addendum (DPA) and Atlassian’s Privacy Policy.
1. Data Collection & Usage
Data covered
“Customer Data” includes any data, content, or materials submitted by the customer or its users through Atlassian Cloud Products, including data received from enabled third-party products. This could include:
- Account and user information
- Project, ticket, message, document, code, and other business content
- Data uploaded or generated through integrations
- Information provided to Atlassian for Support or Advisory Services (“Customer Materials”)
The agreement does not list specific personal-data categories. The DPA and Privacy Policy should be reviewed for details about account, device, usage, analytics, cookies, and support-related information.
How Atlassian may use it
Atlassian may process Customer Data for the purposes identified in the DPA, including providing, securing, maintaining, and supporting the Products. Customers remain the owners of their Customer Data.
Atlassian promises an information-security program with physical, technical, and organizational safeguards and independent audits/certifications. However, it does not promise uninterrupted or error-free service.
2. User Rights
The agreement itself gives users no detailed, direct rights to access, correct, delete, or restrict personal data. Those rights are generally addressed in the DPA and Privacy Policy and may depend on applicable law, such as GDPR or other privacy laws.
Practical rights and controls include:
- Customers can retrieve Customer Data using procedures in the Documentation.
- Following termination, Atlassian will generally delete Customer Data in accordance with the Documentation, unless law prevents deletion.
- Customer administrators may manage accounts associated with the organization’s domain, including taking over existing accounts as “managed accounts.”
- Customers must ensure they have provided required notices and obtained all necessary consents for Atlassian’s processing.
3. Third-Party Sharing
Atlassian may use affiliates and subcontractors to perform its obligations, while remaining responsible for overall performance and maintaining appropriate written agreements.
Customers may enable third-party apps, integrations, and Marketplace products. Enabling one may allow:
- The third-party provider to access Customer Data
- Atlassian to receive data from that third-party product
- Data to be processed under the third party’s own terms and privacy policy
Atlassian does not control or warrant third-party products and disclaims liability for them. Customers should conduct separate vendor and data-security reviews before enabling integrations.
Atlassian may also disclose information when required by law, subpoena, court order, or governmental authority.
4. AI/ML Training
The agreement confirms that Cloud Products may include AI features governed by separate AI Terms. It does not state in this document whether Customer Data is used to train Atlassian’s or third-party AI models.
Users should review the AI Terms and DPA before using AI features, particularly for:
- Whether prompts, inputs, outputs, or feedback are retained
- Whether data is used for model training or improvement
- Which AI providers process the data
- Available opt-outs and enterprise controls
- Whether sensitive or confidential information may be submitted
Do not assume that Customer Data is excluded from AI training based solely on this agreement.
5. Key Obligations and Restrictions
Customers must:
- Use Products only for internal business purposes and within the purchased “Scope of Use”
- Ensure users comply with the agreement, Documentation, and Acceptable Use Policy
- Keep login credentials confidential and promptly report unauthorized access
- Ensure users are at least 16
- Obtain necessary consents and rights for submitted data
- Avoid uploading HIPAA-regulated health information unless a Business Associate Agreement is in place
Users may not resell, sublicense, provide unauthorized third-party access, reverse engineer, bypass usage limits, create competing products, modify products except as expressly allowed, or remove proprietary notices.
Subscriptions generally renew automatically at then-current rates. Fees are ordinarily non-refundable, although a 30-day initial-product return policy applies in specified circumstances.
6. Liability & Disputes
- Disputes for customers in Europe, the Middle East, or Africa generally use Irish law and Irish courts.
- Other customers generally use California law and courts in San Francisco.
- Indirect damages—including lost data, profits, business interruption, and consequential damages—are broadly excluded.
- General liability is capped at fees paid for the affected Products and services during the preceding 12 months.
- Unauthorized disclosure of Customer Data caused by Atlassian’s security-program breach has a higher cap: the lesser of twice those fees or US$5 million.
- The cap does not protect certain claims, including customer restrictions/obligation breaches and some confidentiality claims.
- Free or beta products have no warranty or SLA and liability is capped at US$100.
7. Changes to the Agreement
Atlassian may amend the agreement and incorporated policies by posting changes online, using commercially reasonable efforts to provide at least 30 days’ notice.
For paid subscriptions, changes generally apply at the next order or renewal. Changes may take effect during an existing term if required by law or related to product functionality. Customers may object by terminating the affected subscription within 30 days of notice, generally receiving a refund of prepaid unused fees. Notices may appear by email, website, or within the Products; customers can subscribe to update notifications.
Change history
2026-08-31 · Terms
Summary
The provided diff states only:
> “Added approximately 59 words to the document”
It does not include the actual added language, nor any deletions or replacements. As a result, no substantive legal analysis can be performed.
AI Training and Customer Data
- The diff does not identify whether customer data may be:
- Used to train, fine-tune, or improve AI models;
- Combined with other customers’ data;
- Reviewed by humans or shared with service providers;
- Retained after termination;
- Used in de-identified, anonymized, or aggregated form; or
- Used to develop commercial products or services.
- No conclusion can be reached about whether the agreement expands, restricts, or otherwise changes the provider’s rights to use customer data for AI-related purposes.
Risk Assessment
The principal risk is insufficient information. A meaningful review requires the actual 59 added words and, if applicable, the surrounding provisions that define:
- “Customer Data”;
- “Usage Data,” “Aggregated Data,” or “De-identified Data”;
- Model training, service improvement, or product development;
- Data ownership and licensing rights;
- Confidentiality and security obligations; and
- Opt-out, consent, or deletion rights.
Please provide the actual text of the additions, deletions, and replacements for a substantive analysis.
2026-08-30 · Terms
Summary of Important Changes
1. AI terms are expressly incorporated
- The Agreement now defines “AI Offerings” by reference to Atlassian’s separate AI Terms.
- The AI Terms are expressly included within “Product-Specific Terms” and therefore form part of the Agreement.
- This makes the AI Terms contractually binding when the customer uses applicable AI features, even though the AI Terms are hosted separately online.
Risk: The diff does not state the detailed rules governing AI inputs, outputs, retention, sharing, or model training. Those provisions must be reviewed in the linked AI Terms. In particular, confirm whether Atlassian may use Customer Data, prompts, outputs, or usage information to train, fine-tune, evaluate, or improve AI models, and whether any opt-out or enterprise restriction applies.
2. No express AI-training permission appears in this diff
- The provided changes do not expressly add language authorizing Atlassian to train AI models using Customer Data.
- They also do not expressly prohibit such use.
- The new incorporation of the AI Terms may nevertheless introduce those rights indirectly.
Practical concern: The Agreement treats Customer Data as confidential information, but confidentiality protections do not necessarily prevent permitted use under the DPA, Privacy Policy, Product-Specific Terms, or AI Terms. Review all incorporated documents together for conflicting or broader data-use permissions.
3. Customer Data definition is broad
- Customer Data is defined to include data, content, or materials provided by the customer or its Users through Cloud Products, including data originating from Third-Party Products.
Risk: Data imported from connected applications may be covered by Atlassian’s contractual data-use terms. Customers should assess whether prompts, tickets, source code, personal data, confidential business information, or third-party content could be submitted to AI Offerings.
4. Liability treatment for Customer Data confidentiality claims changed or clarified
- “Excluded Claims” now excludes confidentiality claims relating to Customer Data or Customer Materials from the otherwise broader confidentiality carve-out.
- This appears to place such claims under the Agreement’s ordinary liability framework rather than treating them as fully uncapped claims.
- Separately, unauthorized disclosure of Customer Data or Customer Materials remains a “Special Claim,” subject to the special liability cap— the lesser of the specified multiple of fees and US$5 million.
Risk: Recovery for a data disclosure may be substantially limited, particularly for customers with significant data-related exposure.
5. Other notable changes
- The Agreement is stated to be effective August 17, 2026.
- The introduction and navigation have been reorganized; most edits are stylistic or punctuation changes.
- “Support” is now tied to a separately linked Support Policy, adding another incorporated external document.
- Existing references to online Policies, Product-Specific Terms, and other documents remain important because those materials may be updated under the Agreement’s modification provisions.
Action: Obtain and preserve the AI Terms, DPA, Privacy Policy, Security Measures, and relevant Product-Specific Terms as of the effective date, and verify their model-training and data-retention provisions.
2026-08-26 · Privacy Policy
2026-08-25 · Privacy Policy
2026-08-23 · Terms
Structured Summary of Important Changes
1. New effective date and agreement presentation
- The revised Agreement states: “Effective starting: August 17, 2026.”
- The introduction and navigation have been substantially reorganized, with references to products, users, cloud products, software products, customer obligations, third-party products, support, billing, warranties, liability, confidentiality, and other sections.
- Most changes throughout the text replace typographic apostrophes and quotation marks with standard keyboard punctuation. These appear non-substantive.
2. AI offerings and AI terms expressly incorporated
The most important substantive change is the addition of AI-related defined terms:
- “AI Offerings” means AI offerings described in the AI Terms.
- “AI Terms” means Atlassian’s AI terms available at its legal website.
- The definition of “Product-Specific Terms” now expressly includes the AI Terms.
- “Agreement” is defined to include the Product-Specific Terms, DPA, and Policies, meaning the AI Terms are incorporated into the contractual framework when applicable.
Data-training implications
- This diff does not itself state whether Customer Data may be used to train, fine-tune, evaluate, or improve AI models.
- However, by expressly incorporating the separate AI Terms, the contractual treatment of Customer Data for AI purposes may now be governed by those linked terms.
- The AI Terms should be reviewed specifically for:
- Whether Customer Data, prompts, outputs, usage data, or telemetry may be used for model training or service improvement;
- Whether Atlassian uses third-party AI providers;
- Opt-out or administrative controls;
- Retention, deletion, and de-identification practices;
- Whether customer-specific or shared models are used;
- Restrictions on sensitive, personal, regulated, or confidential information.
- Customers should not assume that the general confidentiality provisions alone prohibit AI training. The separate AI Terms, DPA, Privacy Policy, and product documentation may qualify or supplement those protections.
3. Customer Data definition clarified
“Customer Data” is expressly defined as data, content, or materials provided to Atlassian by or through the Cloud Products, including data originating from Third-Party Products.
This broadens or clarifies the data covered by the Agreement and may bring integrated-app data within the contractual data framework. Customers should confirm that third-party app terms do not grant conflicting rights to use that data.
4. Liability treatment for Customer Data confidentiality claims
The definition of Excluded Claims now states that confidentiality breaches are excluded from that category “but excluding claims relating to Customer Data or Customer Materials.”
This appears intended to prevent confidentiality claims involving Customer Data or Customer Materials from being treated as Excluded Claims. The precise financial effect depends on the surrounding liability provisions, including the general cap and the separate cap for Special Claims involving unauthorized disclosure of Customer Data.
5. Other notable changes
- A formal definition of “Support Policy” has been added, linking support entitlements to Atlassian’s online support documentation.
- The introduction now expressly refers to “deployment options” and the Agreement’s broader coverage.
- The revised page adds links to related content, the Data Transfer Impact Assessment, policy-update notifications, and the subprocessor list. These may facilitate access to important incorporated documents but do not necessarily change the operative rights by themselves.
Recommended action
Before accepting the revised Agreement, review the AI Terms, DPA, Privacy Policy, Product-Specific Terms, and subprocessor list, with particular attention to Customer Data training and model-improvement rights.
2026-08-22 · Privacy Policy
2026-08-21 · Privacy Policy
2026-08-21 · Terms
Summary of Important Changes
Effective Date and Agreement Structure
- The revised agreement is stated to be effective August 17, 2026.
- The introduction has been reorganized into a detailed table of contents and expanded to state that the agreement covers Atlassian’s products, services, and deployment options.
- The agreement continues to apply to Customer’s orders for Products and related Support and Advisory Services, including use by Affiliates for internal business purposes.
- The definition of “Agreement” expressly includes:
- The Customer Agreement;
- Product-Specific Terms;
- The Data Processing Addendum (DPA); and
- Atlassian’s Policies.
- The definition of “Product-Specific Terms” now expressly identifies the AI Terms as included terms.
AI and Customer Data
- New defined terms have been added:
- “AI Offerings” means AI offerings described in the AI Terms.
- “AI Terms” means Atlassian’s separate AI terms available at its website.
- This is an important structural change because the AI Terms are incorporated into the Agreement and may govern the use of Atlassian AI features.
- The provided diff does not show the substantive AI Terms, including whether Customer Data:
- May be used to train, fine-tune, or improve Atlassian or third-party AI models;
- Is used for product development, analytics, or service improvement;
- Is excluded from model training by default or only upon opt-out;
- May be retained in prompts, outputs, logs, or abuse-monitoring systems; or
- May be shared with AI subprocessors.
- Accordingly, the principal AI-related risk is that important data-use permissions or restrictions may exist in the separately linked AI Terms rather than in the main Agreement. Customers should review those terms and confirm whether they provide an explicit no-training commitment, appropriate data-retention limits, confidentiality protections, and controls over third-party model providers.
Customer Data Definition
- “Customer Data” is defined to include data, content, or materials provided to Atlassian by Customer or its Users through Cloud Products, including data originating from Third-Party Products.
- This broad definition may bring data submitted through integrations or marketplace applications within the Agreement’s data and confidentiality framework, but it does not itself clarify whether such data can be used for AI training.
Other Notable Changes
- A formal definition of “Support Policy” has been added, with a link to Atlassian’s support offerings documentation.
- The definition of “Support” now expressly refers to the Support Policy.
- The definition of “User” is clarified to include employees, contractors, business contacts, invited individuals, managed-account users, and individuals interacting with a Product as the Customer’s customer.
- Most remaining changes appear to be editorial: capitalization, punctuation, typographic quotation marks, possessive forms, navigation links, and formatting. No clear substantive change to liability caps, indemnities, confidentiality obligations, termination rights, or renewal mechanics is apparent from the supplied diff.
2026-08-21 · Privacy Policy
2026-08-20 · Privacy Policy
2026-08-19 · Privacy Policy
Between 2019-07-02 and 2019-10-23 · Terms
Between 2018-03-09 and 2018-10-20 · Privacy Policy
Between 2017-06-24 and 2018-03-09 · Privacy Policy
Between 2017-03-15 and 2017-06-24 · Privacy Policy
Between 2016-08-28 and 2017-03-15 · Privacy Policy
Between 2014-04-27 and 2016-08-28 · Privacy Policy