Postman
postman.comPostman is an AI-native API development platform (developer infrastructure / enterprise SaaS). The analyzable documents were a sweepstakes rules page and the main Privacy Policy (Last Updated April 2026). The privacy policy is reasonably detailed and current, covers AI processing by reference to a separate AI Terms document, and Postman certifies to the EU-U.S./UK/Swiss Data Privacy Frameworks. However, several key documents referenced in the privacy policy — the Postman Terms of Service, AI Terms, Sub-processors list, DPA, and Security/Trust page — were NOT supplied, so input/output ownership, training-use specifics, and security controls cannot be verified from source text. The policy permits sharing of cookie-derived visitor data with advertising partners, retains only limited opt-out granularity, and is silent on formal certifications (SOC 2, ISO). Users handling sensitive or proprietary API data should review the unsupplied Terms, AI Terms, and DPA before relying on the platform in regulated contexts.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
The privacy policy refers to user-submitted content as "Your Content" and states "We do not sell that content; it is yours," implying users retain ownership. However, the governing Terms of Service that would define the actual ownership and license grant was not supplied, so the full ownership terms cannot be confirmed from source text.
Output Data Ownership
The supplied privacy policy does not address ownership of AI-generated outputs. Output ownership would be governed by the Postman AI Terms and Terms of Service, neither of which was accessible. This silence is a risk signal given the product ships AI generation features.
Training Data Usage
The policy states Postman may use information provided to develop AI tools and systems, explicitly deferring the details to the separate Postman AI Terms document, which was not supplied. It also states it may anonymize data and use "collective learnings" to improve Services. Because the controlling AI Terms are unavailable, the scope and any opt-out of training use cannot be verified.
Data Retention & Deletion
The policy provides a general retention principle and a specific account-information retention window (active plus 15 days), and it offers deletion rights and account deletion. However, it notes some content may remain after account deletion for team use, and there is no formal deletion SLA or security/audit-log retention schedule. Retention is otherwise tied to "as long as necessary."
Third-Party Data Sharing
Postman states it does not sell information that directly identifies users, but it discloses that visitor information collected via cookies and tracking technologies, including hashed contact information, may be provided to advertising and marketing partners. It also shares data with service providers, affiliates, reseller partners, and in business transfers. The advertising/tracking-data sharing goes beyond what the core API-platform service strictly requires, warranting a moderate rating.
Opt-Out Rights
The policy provides multiple concrete opt-out mechanisms: unsubscribing from promotional email, cookie/tracking opt-out via Privacy Settings, a "Your Privacy Choices" flow for sale/sharing/targeted advertising, and recognition of the Global Privacy Control browser signal. US State Privacy Law and GDPR-style rights (object, withdraw consent, opt out) are enumerated.
Compliance & Certifications
Postman certifies to the EU-U.S. Data Privacy Framework, its UK Extension, and the Swiss-U.S. DPF, with reference to the Department of Commerce certification — a genuine third-party-verifiable attestation. It also describes GDPR, CCPA and multiple US state privacy law alignment. However, no SOC 2, ISO 27001/27017/27018/42001, or NIST framework certifications are mentioned in the supplied text (the Security/Trust page was not accessible), which is a gap for a developer-infrastructure/enterprise tool.
Model Explainability & Auditability
The supplied documents contain no information about model explainability, transparency into AI behavior, or enterprise auditing of AI outputs. The product ships an AI Engineer and Agent Mode, but the accessible policy text is silent on how those models can be inspected or audited. This silence, given AI-first product positioning, is a material gap.
Security Practices & Breach History
The policy references "industry standard technical and organizational measures" and points to a dedicated Security at Postman page (which was not accessible), and describes server-side scanning for tokens, malware, and vulnerabilities. However, no specifics on encryption, penetration testing, bug bounty, or incident response are present in the supplied text, and no breach disclosures appear. Specific controls could not be verified because the trust/security page was inaccessible.
Enterprise vs. Consumer Risk Delta
The policy distinguishes between individual users and managed/organizational accounts, noting that where Postman operates under contract with an organization it acts as data processor per the organization's instructions rather than this Policy. Retention for managed accounts is controlled by the administrator. No enterprise DPA or MSA was supplied, so the concrete data-handling differences between free and paid tiers cannot be fully assessed.
Human Review of User Inputs
The policy states Postman personnel do not access private workspace content except for enumerated purposes (security, support, service integrity, legal obligations, suspected legal violations, or with consent), and reserves the right to scan servers for tokens and malware. This is a reasonably scoped access model, but staff access to private content is expressly permitted under multiple conditions.
Regulatory & Litigation Exposure
The policy describes cooperation with lawful government and law enforcement requests and enforcement of its rights, and notes it is subject to the investigatory and enforcement powers of the FTC regarding its DPF compliance. It also describes dispute-resolution via JAMS for DPF complaints. No active litigation or specific government-request statistics are disclosed.
PII & SPI Data Inventory
Postman collects significant PII: account/profile data, contact and billing information, IP address, device identifiers, usage/interaction data, and inference data. It expressly states it does not intentionally collect Sensitive Personal Information and does not knowingly collect from children under 13 (US) / 18 (outside US). Because notable PII is collected with disclosure and some controls, but includes tracking-derived inferences shared with advertisers, a moderate rating applies.
Policy–Product Currency
The Privacy Policy is dated "Last Updated: April 2026," well within 12 months of the analysis date, and it does address AI development by referencing the Postman AI Terms — matching the product's AI-native positioning (AI Engineer, Agent Mode). However, the policy covers AI only by cross-reference to an unsupplied document and does not detail third-party model providers or AI data flows, so coverage of the shipped AI capabilities is only partial, capping the rating at YELLOW.
Cross-Document Consistency
Two documents were supplied: a sweepstakes Official Rules page and the Privacy Policy. These govern different scopes and the sweepstakes rules explicitly subordinate themselves to (yet take precedence over) the general Terms and Privacy Policy for that promotion only. The core Terms of Service, AI Terms, and DPA were not retrievable, so a full cross-document consistency check across the primary legal documents is not possible. The precedence clause creating a promotion-specific override is a minor tension worth noting.
You've read all 15 risk ratings for Postman. Create a free account to see the exact policy wording behind each rating.