Privacy Policy
We believe developer privacy is a non-negotiable standard. Learn how IPPost safeguards your credentials, collections, and private API network requests.
Our Zero-Inspection Guarantee
Your API requests, endpoints, private headers, Bearer tokens, and secrets are strictly confidential to you and your team. We never log, inspect, resell, or train AI models on user API traffic.
1. Local-First & Zero-Inspection Architecture
IPPost is engineered from the ground up on a fundamental developer privacy tenet: Zero-Inspection Execution. When you execute HTTP requests, GraphQL queries, WebSocket messages, or gRPC calls through the native IPPost desktop engine or local proxy relay:
- Your request bodies, query parameters, Bearer tokens, API keys, and custom headers travel directly between your machine and your designated destination server.
- We never intercept, route, log, inspect, store, or monetize your private API traffic or response payloads.
- Localhost traffic (e.g.
http://localhost:3000or internal microservices) never leaves your local network.
2. Information We Collect
We only collect the minimal information necessary to deliver and authenticate the cloud workbench:
- Account Information: Your full name, email address, password hash (encrypted using salt-factored bcrypt), account type (Personal or Organization), and optional company metadata (company name, team size, industry).
- Cloud Workspace Collections: API request definitions, documentation descriptions, environment variable templates, mock server schemas, and monitor configurations that you explicitly save to cloud workspaces for team collaboration.
- Diagnostic & Crash Telemetry: Anonymous crash reports and platform version details (e.g., macOS ARM64 vs Windows x64) to maintain desktop engine binary stability.
3. How We Use Your Information
We process your information solely for the following legitimate purposes:
- Authenticating your user session and managing workspace role-based permissions (Viewer, Editor, Admin, Owner).
- Synchronizing your collections, environments, and mock servers across your devices in real-time.
- Dispatching critical operational emails, such as email verification links, workspace invitation notices, and security alerts.
- Preventing automated abuse, unauthorized brute-force attempts, and platform outages.
4. Enterprise Data Security & Encryption
We employ industry-leading security practices to safeguard all customer data:
- Encryption in Transit: All data transmitted between your browser/desktop client and our cloud infrastructure is encrypted with modern TLS 1.3 / HTTPS.
- Encryption at Rest: Cloud databases and snapshot backups are encrypted using military-grade AES-256 encryption.
- mTLS & Certificate Isolation: Custom client certificates and private keys used for mutual TLS testing are stored strictly in your local isolated session or encrypted vaults.
5. GDPR, CCPA & Your Privacy Rights
Under the European General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA), you enjoy comprehensive rights over your personal information:
- Right to Access: You can request a complete copy of all personal data stored about you.
- Right to Rectification: You may update or correct your profile and organization data at any time.
- Right to Erasure (Right to be Forgotten): You can permanently delete your account, personal workspaces, and associated collections.
- Right to Data Portability: You can export your collections in Postman v2.1 or OpenAPI 3.0 compatible JSON formats at any time.
6. Third-Party Sub-processors
We only engage reputable sub-processors bound by strict Data Processing Agreements (DPAs):
- Cloud Database Infrastructure: Encrypted PostgreSQL clusters hosted in SOC 2 Type II certified data centers.
- Email Transmission: Verified transactional email delivery providers (e.g. Resend) for verification and invite notifications.
8. Contact Data Protection Officer
If you have questions regarding this Privacy Policy, wish to exercise your GDPR/CCPA rights, or require a signed Data Processing Agreement (DPA) for your organization, please contact our Data Protection Officer at:
Email: privacy@ippost.app
Subject: Privacy Data Request / DPA Inquiry
Need a Custom DPA or Privacy Audit?
We provide enterprise Data Processing Agreements and security questionnaires for compliance teams.