I’m trying to understand the data-handling implications of the new Atlassian × Gamma integration, particularly for organizations where Jira and Confluence contain confidential or regulated information.
The integration is quite interesting from a productivity perspective — Gamma can use Jira and Confluence context to create presentations, and Atlassian describes this as being enabled through the Atlassian MCP Server and Teamwork Graph.
However, I’m looking for some clarification around what happens to the Atlassian data once it is passed to Gamma.
From the current Atlassian documentation, I understand that:
- The Gamma integration uses a third-party MCP server.
- Data may be sent from the Atlassian environment to the third-party MCP.
- Atlassian’s own data-handling commitments do not apply while that data is being processed or stored in the third-party environment.
This raises a few questions for me:
1. What exactly is sent to Gamma?
When a user asks Gamma to create a presentation based on Jira issues or Confluence pages, is the relevant Jira/Confluence content sent to Gamma in full, or is only the minimum required context/content transferred?
2. What does Gamma retain?
Does Atlassian have any visibility or contractual requirements around how long Gamma retains the Jira/Confluence content received through the MCP integration?
3. Is the data used for AI model training?
Does Gamma use any Jira/Confluence data received through the Atlassian MCP integration to train, fine-tune, or improve its models or services?
4. Does Atlassian Enterprise/ZDR coverage extend to this integration?
Atlassian's own Rovo documentation describes strong data-handling protections, including ZDR arrangements with its third-party LLM providers. Does any equivalent protection apply when data is sent to Gamma through the third-party MCP integration?
5. What should enterprise customers do with confidential data?
For an organization with sensitive IP, customer information, security information, or regulated data in Jira/Confluence, is the recommended approach to avoid using the Gamma integration for those projects/content areas, unless the organization has separately reviewed and approved Gamma's data-handling terms?
To clarify, I am not questioning the value of the integration — I think the use case is genuinely interesting. I am mainly trying to understand the security and data-governance boundary between Atlassian and Gamma before recommending this capability in an enterprise environment.
If someone from Atlassian or Gamma can point to the relevant documentation, contractual terms, security documentation, or data-flow documentation, that would be very helpful.
In particular, I would be interested in an official answer to:
What happens to Jira/Confluence data after it leaves Atlassian through the Gamma MCP integration, and what protections apply to that data while it is in Gamma's environment?