deep-dive

What Your Productivity Apps Know About You

Jira, Confluence, Slack, and Notion hold more personal data than most people realize. Here's what they collect and who has access to it.

Most people think of productivity apps as neutral tools — places where work happens, not places where personal data accumulates. But after years of daily use, the major platforms in this category hold a detailed record of your professional life that is accessible to more parties than most users realize.

This is what’s actually stored, who can access it, and why it matters for how you handle anything sensitive in work contexts.


What Jira Holds

Jira is primarily known as an issue tracker, but its actual data footprint is considerably broader.

Issue content includes the titles, descriptions, and comments on every bug report, feature request, task, and incident. In practice, this means years of discussion about technical decisions, client requirements, security vulnerabilities, and internal disagreements about product direction.

Assignment and mention history records who was responsible for which tasks, across every project ever tracked. This amounts to granular performance data — which engineer missed a deadline, which project manager resolved a blocker, who was involved in a post-incident review.

Audit logs capture user actions within the system: who viewed which issue, who changed a field, who exported a report, and when. These logs are typically available to administrators.

Attachments can include screenshots, design documents, error logs, and files of any type uploaded to issues. A screenshot attached to a bug may contain customer personal information. An error log may contain system data that was never intended for a third-party SaaS platform.

Who Can Access Jira Content

  • Atlassian administrators within your organization have access to all workspace content
  • Atlassian itself can access your data for support purposes
  • Starting August 17, in-app content from Jira (issue titles, descriptions, comments) may be used to train Atlassian’s AI products unless opted out by an organization admin
  • Sub-processors, including in some cases OpenAI, may receive content as part of AI feature processing

What Confluence Holds

If Jira is the record of what your team did, Confluence is the record of how your organization thinks.

Architecture documentation includes decision records, runbooks, system diagrams described in text, and specifications for products and infrastructure. These are detailed maps of exactly how your systems work.

Meeting notes and planning documents capture strategy discussions, retrospectives, hiring conversations, and planning sessions. The content often includes information that would be sensitive if it appeared outside the organization.

HR and management documentation — performance review frameworks, compensation band documentation, org charts, hiring rubrics — frequently lives in Confluence because it is a convenient place for collaborative documents that need to be shared with a defined group.

Personal data throughout — employees named in decisions, mentioned in retrospectives, assigned to projects, discussed in performance documentation. Under GDPR, this constitutes personal data whose processing is subject to the platform’s data handling practices.

Who Can Access Confluence Content

Access controls are set by workspace administrators, and in many organizations, Confluence pages are accessible to all employees by default. Atlassian administrators can access all content. Starting August 17, Confluence page bodies may feed AI training pipelines unless opted out. The same sub-processor considerations that apply to Jira content apply here.


What Slack Holds

Slack’s data footprint is particularly broad because of the conversational nature of the platform. Unlike formal documentation in Jira or Confluence, Slack captures the informal communication layer of an organization — and that layer is dense with information.

Message content across all channels a user participates in is stored on Slack’s servers. This includes direct messages, group messages, and channel discussions. Workspace retention settings determine how long this is kept, but many organizations use the default or custom retention periods that preserve messages for extended periods.

File attachments uploaded to Slack include everything from quick screenshots to contract documents shared for quick review. In practice, contract documents, HR communications, financial summaries, and sensitive client information have passed through Slack at most companies that use it.

Communication metadata — who communicated with whom, when, on which channels, with what frequency — is retained independent of message content. Communication pattern data can reveal working relationships, reporting structures, and organizational dynamics that individuals didn’t think they were making visible.

Who Can Access Slack Content

This is the part that surprises most users.

  • On Free and Pro plans, workspace owners can export message data from public channels. Direct messages are not available in bulk export on these plans.
  • On Business+ and Enterprise Grid plans, workspace owners and administrators can request exports that include direct message content, with notice to users required in some jurisdictions.
  • Slack employees can access workspace content — including direct messages — for the purposes outlined in Slack’s privacy policies: support, trust and safety enforcement, and platform operations.

That last point deserves emphasis. The “private” DM in Slack is private from your colleagues on the same workspace. It is not private from Slack itself. This is not unique to Slack — it applies to any messaging platform that stores content on its servers unencrypted in a form accessible to employees.


What Notion Holds

Notion’s flexible block-based structure makes it a common home for everything from quick meeting notes to detailed strategic planning documents to sensitive HR content. That flexibility is also what makes it a significant data holder for the organizations that adopt it comprehensively.

Page content includes anything written in a Notion page: business strategies, financial models, customer databases built as Notion tables, hiring pipelines, product roadmaps, and personal notes kept in a work workspace.

Database records can contain structured personal information — customer contact details, employee records, vendor information, project stakeholder data — depending on how the workspace is set up. Organizations that use Notion as a lightweight CRM or HR database are storing substantial personal data within the platform.

Comment history on pages captures discussion about sensitive documents that might otherwise have been handled in private email.

Who Can Access Notion Content

  • Notion employees can access workspace content for support and platform integrity purposes
  • When Notion AI features are active, content from the page being processed is sent to Notion’s AI infrastructure and, under Notion’s published terms, to third-party providers including OpenAI under data processing agreements
  • Workspace administrators have broad access to workspace content, which in many organizations includes content an employee assumed was only visible to specific collaborators

The Personal Files Problem

The problem with personal data in work tools is not that your IT administrator might be watching. It is the cumulative consequence of data accumulation in platforms with multiple parties in the access chain.

When you store a personal document in a work productivity tool — a medical record scanned for an insurance reimbursement, a legal document related to a personal matter, a personal photo uploaded to use in a presentation — that document inherits the privacy posture of the entire platform. It becomes accessible to:

  • Your organization’s administrators
  • The platform company itself
  • The platform’s sub-processors and AI training pipelines
  • Parties who receive data through legal demands or breach

This is not a hypothetical concern. Legal discovery in commercial disputes regularly sweeps Slack messages, Jira tickets, and Confluence pages. Government investigations have subpoenaed SaaS provider data. Data breaches at SaaS companies have exposed enterprise customer content including files employees didn’t realize were retained.


What “Your” Files in a Work Tool Actually Means

The assumption that files stored in a work tool primarily belong to you is worth examining.

In most employment relationships, files created in work tools on company accounts are company property. Even if you uploaded a personal document incidentally — to share with a colleague, to print from the office, to include in a presentation — it may be considered within the scope of the employer’s data ownership. Your ability to access, export, or delete that document depends on the employer’s policies and the platform’s data portability features, not on your sense of ownership.

When you leave a job, most work tool accounts are closed. Files you created or uploaded within those tools typically remain on the employer’s account, not yours. The contacts, files, and documents you worked with may be inaccessible the day after your last day.


Mapping the Access Hierarchy

The entity that can reach your files depends on which tool you’re using and in what context. Here’s a simplified map:

ContextEmployer can accessPlatform can access
Personal Google accountNoYes
Google Workspace (work)Yes (admin)Yes
Slack on a work workspaceYes (plan-dependent)Yes
Jira on company instanceYesYes
Confluence on company instanceYesYes
Notion on shared workspaceYesYes
Personal iCloudNoYes
daftei personal accountNoLimited (encrypted storage)

The pattern holds within each category. Work tools on company accounts come with employer access as a design feature — administrators need to manage the organization’s data. Personal accounts on mainstream platforms give the platform itself access, even when your employer cannot reach it.


A Practical Rule for Personal Files

The simplest version of this is a rule about categorization: work tools are for work files, and personal tools are for personal files.

Files that need to stay genuinely private — personal photos, sensitive documents, health records, private correspondence, legal documents for personal matters — don’t belong in work productivity tools. Not because your employer is necessarily looking, but because you are accepting terms designed for organizational collaboration, with the access model that entails.

Those files belong somewhere designed for personal, private storage — where you understand who can access what, what happens if you change jobs, and what the data deletion policy is.

Work tools are excellent at what they’re designed for. They are not designed to be the private file store for your personal life. Treating them as such means accepting a privacy posture you probably wouldn’t choose if you thought about it explicitly.

The practical implication: audit what personal content you’ve accumulated in work tools over time. Download anything you want to keep. Store personal files somewhere designed for personal use. And when you do need to store something privately and long-term, choose a platform whose access model matches what you actually want.

Your memories deserve better than an ad platform.

Try daftei free →
← All posts