I've contacted them earlier and they admitted that they collect the HTTP payload that you send and receive with it and it is stated in their privacy policy. You probably shouldn't be using it to test API with credentials or sensitive data because it might be a GDPR or other legal violation in your region. |
https://learning.postman.com/docs/postman/launching-postman/...
So then, if you create a postman account so that you can sync data between different computers you use, it will do exactly that, including request and response history.
If you don't create a postman account it doesn't do that.
They are NOT collecting your payloads unless you ask them to, and they are NOT doing it secretly as might be implied by the phrasing OP used with "they admitted".
It's also worth mentioning it sounds like Insomnia has the exact same feature: https://support.insomnia.rest/category/31-cloud-account