8 Total
1 High severity
7 Medium severity
0 Low severity
Summary

This is Postman's Terms of Service, the legal agreement you accept when you create an account or use Postman's API development and testing tools. The most important thing to know is that the agreement limits Postman's financial liability to you to the amount you paid in the last 12 months (or $100 if you haven't paid anything), meaning that if Postman's platform causes significant harm or data loss, your ability to recover damages is sharply capped. If you store sensitive or proprietary API data in Postman workspaces, review what data you upload carefully, as the terms grant Postman a broad content license and the Acceptable Use Policy governs what data may be retained or removed.

Technical / Legal Breakdown

This document governs use of Postman's API platform services, including its desktop application, web interface, and cloud features, on the basis of a click-wrap agreement between users and Postman, Inc. The agreement states that users grant Postman a worldwide, non-exclusive, royalty-free license to use content submitted to the platform, the terms authorize Postman to suspend or terminate accounts for violations of its Acceptable Use Policy without prior notice, and the agreement limits Postman's liability to fees paid in the preceding twelve months or one hundred dollars, whichever is greater. The liability cap combined with a mutual indemnification obligation placed on users is operationally notable for enterprise customers, as the terms authorize Postman to modify the service and pricing with notice periods that may be shorter than enterprise procurement cycles require; the agreement asserts California law as governing and the courts of San Francisco County as exclusive venue, which may engage conflict-of-law analysis for non-US users, though applicable law in certain jurisdictions may limit the enforceability of these forum selection and choice-of-law clauses. The terms engage GDPR and CCPA frameworks through reference to a separate Privacy Policy, with the DPA (Data Processing Addendum) incorporated by reference for enterprise customers processing personal data of EU/EEA individuals; California residents are afforded specific rights under CCPA, and the agreement's data license provisions warrant review under both frameworks for enterprise compliance teams assessing whether user-submitted API data may constitute personal data subject to those regulations.

Institutional Analysis

Institutional analysis available with Professional

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.

Start Professional free trial
High — 1 provision
Medium — 7 provisions

Monitoring

Postman has updated this document before.

Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →

Professional Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Professional free trial

Cross-platform context

See how other platforms handle Account Suspension and Termination and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

DSA
European Union
View official text ↗
FAA
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured May 5, 2026 06:36 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000677
Version ID CA-V-001315
SHA-256 5af3ad28ffd0b87170025ca63aef45be16d40cb71e1a5def36e2bd1209cb6f4c
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans