Postman logo

Postman

postman.com
Moderate Risk
Updated September 4, 2026

Postman is an AI-native API development platform (developer infrastructure / enterprise SaaS). The analyzable documents were a sweepstakes rules page and the main Privacy Policy (Last Updated April 2026). The privacy policy is reasonably detailed and current, covers AI processing by reference to a separate AI Terms document, and Postman certifies to the EU-U.S./UK/Swiss Data Privacy Frameworks. However, several key documents referenced in the privacy policy — the Postman Terms of Service, AI Terms, Sub-processors list, DPA, and Security/Trust page — were NOT supplied, so input/output ownership, training-use specifics, and security controls cannot be verified from source text. The policy permits sharing of cookie-derived visitor data with advertising partners, retains only limited opt-out granularity, and is silent on formal certifications (SOC 2, ISO). Users handling sensitive or proprietary API data should review the unsupplied Terms, AI Terms, and DPA before relying on the platform in regulated contexts.

AI Transparency Facts

Independent analysis by TermsWatchdog · © 2026 TermsWatchdog

Input Data Ownership

Moderate Risk

The privacy policy refers to user-submitted content as "Your Content" and states "We do not sell that content; it is yours," implying users retain ownership. However, the governing Terms of Service that would define the actual ownership and license grant was not supplied, so the full ownership terms cannot be confirmed from source text.

Confidence
45%

Output Data Ownership

Moderate Risk

The supplied privacy policy does not address ownership of AI-generated outputs. Output ownership would be governed by the Postman AI Terms and Terms of Service, neither of which was accessible. This silence is a risk signal given the product ships AI generation features.

Confidence
20%

Training Data Usage

Moderate Risk

The policy states Postman may use information provided to develop AI tools and systems, explicitly deferring the details to the separate Postman AI Terms document, which was not supplied. It also states it may anonymize data and use "collective learnings" to improve Services. Because the controlling AI Terms are unavailable, the scope and any opt-out of training use cannot be verified.

Confidence
50%

Data Retention & Deletion

Moderate Risk

The policy provides a general retention principle and a specific account-information retention window (active plus 15 days), and it offers deletion rights and account deletion. However, it notes some content may remain after account deletion for team use, and there is no formal deletion SLA or security/audit-log retention schedule. Retention is otherwise tied to "as long as necessary."

Confidence
65%

Third-Party Data Sharing

Moderate Risk

Postman states it does not sell information that directly identifies users, but it discloses that visitor information collected via cookies and tracking technologies, including hashed contact information, may be provided to advertising and marketing partners. It also shares data with service providers, affiliates, reseller partners, and in business transfers. The advertising/tracking-data sharing goes beyond what the core API-platform service strictly requires, warranting a moderate rating.

Confidence
70%

Opt-Out Rights

Low Risk

The policy provides multiple concrete opt-out mechanisms: unsubscribing from promotional email, cookie/tracking opt-out via Privacy Settings, a "Your Privacy Choices" flow for sale/sharing/targeted advertising, and recognition of the Global Privacy Control browser signal. US State Privacy Law and GDPR-style rights (object, withdraw consent, opt out) are enumerated.

Confidence
80%

Compliance & Certifications

Moderate Risk

Postman certifies to the EU-U.S. Data Privacy Framework, its UK Extension, and the Swiss-U.S. DPF, with reference to the Department of Commerce certification — a genuine third-party-verifiable attestation. It also describes GDPR, CCPA and multiple US state privacy law alignment. However, no SOC 2, ISO 27001/27017/27018/42001, or NIST framework certifications are mentioned in the supplied text (the Security/Trust page was not accessible), which is a gap for a developer-infrastructure/enterprise tool.

Confidence
65%

Model Explainability & Auditability

High Risk

The supplied documents contain no information about model explainability, transparency into AI behavior, or enterprise auditing of AI outputs. The product ships an AI Engineer and Agent Mode, but the accessible policy text is silent on how those models can be inspected or audited. This silence, given AI-first product positioning, is a material gap.

Confidence
30%

Security Practices & Breach History

Moderate Risk

The policy references "industry standard technical and organizational measures" and points to a dedicated Security at Postman page (which was not accessible), and describes server-side scanning for tokens, malware, and vulnerabilities. However, no specifics on encryption, penetration testing, bug bounty, or incident response are present in the supplied text, and no breach disclosures appear. Specific controls could not be verified because the trust/security page was inaccessible.

Confidence
50%

Enterprise vs. Consumer Risk Delta

Moderate Risk

The policy distinguishes between individual users and managed/organizational accounts, noting that where Postman operates under contract with an organization it acts as data processor per the organization's instructions rather than this Policy. Retention for managed accounts is controlled by the administrator. No enterprise DPA or MSA was supplied, so the concrete data-handling differences between free and paid tiers cannot be fully assessed.

Confidence
55%

Human Review of User Inputs

Moderate Risk

The policy states Postman personnel do not access private workspace content except for enumerated purposes (security, support, service integrity, legal obligations, suspected legal violations, or with consent), and reserves the right to scan servers for tokens and malware. This is a reasonably scoped access model, but staff access to private content is expressly permitted under multiple conditions.

Confidence
70%

Regulatory & Litigation Exposure

Moderate Risk

The policy describes cooperation with lawful government and law enforcement requests and enforcement of its rights, and notes it is subject to the investigatory and enforcement powers of the FTC regarding its DPF compliance. It also describes dispute-resolution via JAMS for DPF complaints. No active litigation or specific government-request statistics are disclosed.

Confidence
60%

PII & SPI Data Inventory

Moderate Risk

Postman collects significant PII: account/profile data, contact and billing information, IP address, device identifiers, usage/interaction data, and inference data. It expressly states it does not intentionally collect Sensitive Personal Information and does not knowingly collect from children under 13 (US) / 18 (outside US). Because notable PII is collected with disclosure and some controls, but includes tracking-derived inferences shared with advertisers, a moderate rating applies.

Confidence
75%

Policy–Product Currency

Moderate Risk

The Privacy Policy is dated "Last Updated: April 2026," well within 12 months of the analysis date, and it does address AI development by referencing the Postman AI Terms — matching the product's AI-native positioning (AI Engineer, Agent Mode). However, the policy covers AI only by cross-reference to an unsupplied document and does not detail third-party model providers or AI data flows, so coverage of the shipped AI capabilities is only partial, capping the rating at YELLOW.

Confidence
65%

Cross-Document Consistency

Moderate Risk

Two documents were supplied: a sweepstakes Official Rules page and the Privacy Policy. These govern different scopes and the sweepstakes rules explicitly subordinate themselves to (yet take precedence over) the general Terms and Privacy Policy for that promotion only. The core Terms of Service, AI Terms, and DPA were not retrievable, so a full cross-document consistency check across the primary legal documents is not possible. The precedence clause creating a promotion-specific override is a minor tension worth noting.

Confidence
40%

You've read all 15 risk ratings for Postman. Create a free account to see the exact policy wording behind each rating.