This is a print-friendly report. Click Print and choose “Save as PDF” in the destination dropdown to download.

SaaSGuard Risk Report

Confluence

atlassian.com

Generated May 4, 2026

Grade D

Score: 46 / 100

Executive summary

We analyzed Confluence’s Terms of Service across 8 risk dimensions and found 9 flagged clauses across 7 categories.

Flagged clauses by category

AI training on your data (1)

  • Severity 5 · egregious

    If Customer provides Atlassian with feedback or suggestions regarding the Products or other Atlassian offerings, Atlassian may use the feedback or suggestions without restriction or obligation.

    Confluence can use any feedback or suggestions you give them to improve their products without any restrictions or obligation to you.

    Your ideas for improving Confluence could be used to benefit other customers without any compensation to you.

    Matches The New York Times Co. v. OpenAI & Microsoft (2023)

Auto-renewal traps (1)

  • Severity 3 · notable

    Unless otherwise specified in an Order and subject to the Product, Support or Advisory Services continuing to be generally available, a Subscription Term will automatically renew at Atlassian’s then current rates for: (i) if Customer’s prior Subscription Term was for a period less than twelve (12) months, another Subscription Term of a period equal to Customer’s prior Subscription Term, or (ii) if Customer’s prior Subscription Term was for twelve (12) months or more, twelve (12) months. Either party may elect not to renew a Subscription Term by giving notice to the other party before the end of the current Subscription Term. Customer must provide any notice of non-renewal through account settings in the Products, by contacting Atlassian’s support team or by otherwise providing Atlassian notice.

    Confluence automatically renews your subscription for another term, either the same length as before or 12 months, at their current rates. You must notify them through account settings or support at least 30 days before renewal to cancel.

    If you miss the 30-day cancellation window, you're locked into another term at potentially higher prices.

    Matches FTC v. Amazon (Iliad Flow / Prime Enrollment) (2023)

Surprise price hikes (1)

  • Severity 3 · notable

    Unless otherwise specified in an Order and subject to the Product, Support or Advisory Services continuing to be generally available, a Subscription Term will automatically renew at Atlassian’s then current rates for: (i) if Customer’s prior Subscription Term was for a period less than twelve (12) months, another Subscription Term of a period equal to Customer’s prior Subscription Term, or (ii) if Customer’s prior Subscription Term was for twelve (12) months or more, twelve (12) months. Either party may elect not to renew a Subscription Term by giving notice to the other party before the end of the current Subscription Term. Customer must provide any notice of non-renewal through account settings in the Products, by contacting Atlassian’s support team or by otherwise providing Atlassian notice.

    Confluence automatically renews your subscription for another term, either the same length as before or 12 months, at their current rates. You must notify them through account settings or support at least 30 days before renewal to cancel.

    If they raise prices and you miss the 30-day window, you're locked in for another full term at the new price.

    Matches FTC v. MoviePass / Helios and Matheson Analytics (2021)

Data residency (1)

  • Severity 3 · notable

    If Customer is domiciled: (i) in Europe, the Middle East, or Africa, this Agreement is governed by the laws of the Republic of Ireland, with the jurisdiction and venue for actions related to this Agreement in the courts of the Republic of Ireland, or (ii) elsewhere, this Agreement is governed by the laws of the State of California, with the jurisdiction and venue for actions related to this Agreement in the state and United States federal courts located in San Francisco, California.

    This agreement is governed by the laws of Ireland if you're in Europe, the Middle East, or Africa, or by California law if you're elsewhere. Legal disputes will be handled in the courts of Ireland or San Francisco, California, respectively.

    If you have a legal dispute, you'll have to pursue it in a specific, potentially inconvenient, jurisdiction.

    Matches Schrems II (Data Protection Commissioner v. Facebook Ireland) (2020)

Termination friction (1)

  • Severity 3 · notable

    Upon expiration or termination of this Agreement or a Subscription Term: (a) Customer’s rights to use the applicable Products, Support or Advisory Services will cease, (b) Customer must immediately cease accessing the Cloud Products and using the applicable Software Products and Cloud Clients, and (c) Customer must delete (or, on request, return) all license keys, access keys and any Product copies. Following expiration or termination, unless prohibited by Law, Atlassian will delete Customer Data in accordance with the Documentation.

    When your subscription ends, Confluence will delete your data according to their documentation, and you must stop using their products and delete any access keys.

    You need to proactively back up your data before termination, as Confluence will delete it afterward.

    Matches Bungie / Destiny 2 Account Termination Litigation (2023)

Liability caps (2)

  • Severity 4 · material

    Except for Excluded Claims or Special Claims, to the maximum extent permitted by Law, each party’s entire liability arising out of or related to this Agreement will not exceed in aggregate the amounts paid to Atlassian for the Products, Support and Advisory Services giving rise to the liability during the twelve (12) months preceding the first event out of which the liability arose. Customer’s payment obligations under Sections 10.1 (Fees) and 10.2 (Taxes) are not limited by this Section 14.2.

    Confluence's total liability to you for any issue related to this agreement is capped at the amount you paid them in the 12 months before the issue arose.

    If their service causes you a $100,000 loss, the most you can recover from them is the amount you paid them over the last year.

    Matches Capital One Data Breach Class Action — settled for $190M (2022)

  • Severity 4 · material

    Except for Excluded Claims or Special Claims, to the maximum extent permitted by Law, neither party will have any liability arising out of or related to this Agreement for any loss of use, lost data, lost profits, interruption of business or any indirect, special, incidental, reliance or consequential damages of any kind, even if informed of their possibility in advance.

    Confluence limits their liability for most issues to indirect, special, or consequential damages, meaning they won't pay for lost profits or business interruptions.

    If Confluence causes a major outage that costs you significant revenue, they are not responsible for those losses.

    Matches Capital One Data Breach Class Action — settled for $190M (2022)

Right to silently change terms (2)

  • Severity 4 · material

    For paid subscriptions: (i) except as specified below, modifications to this Agreement will take effect at the next Order or renewal unless either party elects to not renew pursuant to Section 10.1(c) (Renewals), and (ii) Atlassian may specify that modifications will become effective during a then-current Subscription Term if: (A) required to address compliance with Law, or (B) required to reflect updates to Product functionality or introduction of new Product features. If Customer objects, Customer may terminate the remainder of the then-current Subscription Term for the affected Products as its exclusive remedy. To exercise this right, Customer must notify Atlassian of its termination under this Section 20.9(c) within thirty (30) days of the modification notice, and Atlassian will refund any pre-paid fees for the terminated portion of the applicable Subscription Term.

    Atlassian can update terms during your subscription if required by law or for product changes, and you have 30 days to object and terminate as your only recourse.

    You might be forced to accept new terms mid-contract or lose access to the product if you disagree.

    Matches X Corp. Verified User Class Action (2024)

  • Severity 4 · material

    Atlassian may modify this Agreement (which includes the Policies, Product-Specific Terms and DPA) from time to time, by posting the modified portion(s) of this Agreement on Atlassian’s website. Atlassian must use commercially reasonable efforts to post any such modification at least thirty (30) days prior to its effective date.

    Atlassian can change the agreement terms at any time, but they will try to give you 30 days' notice by posting changes on their website.

    You could agree to one set of terms today and a totally different set next week with no warning.

    Matches Italian DPA (Garante) v. WhatsApp — settled for $6M (2022)

Methodology

SaaSGuard uses an automated pipeline: a daily Playwright crawler captures each vendor’s public Terms of Service, Privacy Policy, and DPA. Google’s Gemini 2.5 Flash classifies each clause into one of 8 risk categories with a severity score (1–5). Clauses are cross-referenced against a curated database of real lawsuits and FTC actions via embedding-based similarity matching. Grades are computed from per-category max severity; full source code is available on request.

Built for educational and informational purposes. Not legal advice. Always have your own counsel review SaaS contracts before signing.

View live page →