Blossom

Legal

Blossom Legal Center

Version 0.1 — Last updated July 22, 2026

This page is a plain-language guide to Blossom’s legal documents. It does not replace the documents themselves. Blossom is operated by Polymath HQ, Inc., a Delaware corporation based in New York.

Frequently asked questions

In short: Start here for quick answers, then follow the link to the document that controls.

Who owns my data?

You do. Customers retain their rights in Customer Data. Blossom receives only the limited rights needed to provide, secure, maintain, and support the service, comply with law, and enforce the agreement. See the Terms of Service and Data Processing Addendum.

Does Blossom train AI models on my data?

Blossom does not use Customer Data to train, develop, or improve an AI model made available outside your account, and contractually restricts its AI providers from doing so. A high-risk or new AI model that cannot meet those terms can be used in your account only after prior, affirmative, account-specific consent. You may revoke that consent for future use at any time. See the Terms of Service, DPA, and Security Overview.

What can Blossom do during the free Audit?

The Audit is read-only. Blossom reviews the sources you authorize but does not intentionally send, edit, delete, publish, purchase, deposit, file, or otherwise act in connected systems. See the Audit Terms.

How long does Blossom keep data?

Workspace data is kept while the account is active and deleted within 30 days after account deletion. Raw Scout audit artifacts are automatically purged after no more than 90 days, and a user may trigger an earlier purge at the end of onboarding. Billing and tax records remain as long as law requires. Marketing leads and questions remain until the person requests deletion. See the Privacy Policy and DPA.

Which vendors may process customer data?

The Subprocessor List names vendors Blossom hires for infrastructure, AI, agent tooling, integrations, token holding, enrichment, and support. Customer-Connected Services—such as your own Gmail, Microsoft 365, Slack, Zoom, phone, or notetaker account—are governed by your agreement with that provider and are not Blossom subprocessors merely because you connect them.

Can Blossom’s agents call, text, or email people for me?

Yes, for supported channels and properly configured uses—but you must have valid consent and follow messaging, telemarketing, recording, carrier, and email rules. You are the sender or call-maker for communications you initiate or control. Blossom provides guardrails such as supported opt-outs, suppression, disclosures, and quiet hours, which you must keep correctly configured. See the Terms of Service and Acceptable Use Policy.

Can I rely on an AI output without review?

No. AI output may be inaccurate, incomplete, or unsuitable. Customers must evaluate it and use appropriate human or qualified-professional review before acting on or sharing it. Blossom provides no output indemnity. See the Terms of Service.

Does Blossom have a security certification?

Not today. Blossom is actively building toward third-party attestation and does not claim SOC 2, ISO 27001, or another security certification. See the Security Overview.

Does Blossom sell personal information or use ad pixels?

No. Blossom does not sell personal information or share it for cross-context behavioral advertising, and it does not currently use advertising pixels. See the Privacy Policy and Cookie Policy.

How do I exercise a privacy right or report a security issue?

Email legal@blossom.fm. Use the subject “Privacy Request” for an access, correction, deletion, portability, opt-out, or appeal request, and “Security Vulnerability Report” for a vulnerability. See the Privacy Policy and Responsible Disclosure Policy.

Legal documents

In short: These documents cover the customer relationship, privacy, responsible use, vendors, security, and website technologies.

DocumentWhat it covers
Privacy PolicyPersonal information Blossom handles as a controller for its site, leads, accounts, billing relationships, and direct support
Terms of ServiceThe click-through agreement for paid and production Services
Audit TermsShort terms for Blossom’s free, read-only business-process Audit
Data Processing AddendumProcessor and service-provider terms for Customer Personal Data
Subprocessor ListVendors Blossom engages to process Customer Personal Data, plus change notices
Acceptable Use PolicyUniversal safety rules and requirements for communications, high-impact uses, sensitive data, payments, and connectors
Security OverviewBlossom’s current pre-certification safeguards and assurance status
Cookie PolicyEssential and first-party browser technologies and privacy choices
Responsible Disclosure PolicyAuthorized security research, reporting instructions, and safe harbor

Contact

In short: Legal, privacy, and security questions go to legal@blossom.fm.

Polymath HQ, Inc. d/b/a Blossom
New York, United States
Attention: Noah Lenz
legal@blossom.fm

Changelog

In short: This is the first working-draft version.

DateVersionChange
July 22, 20260.1Initial working draft for counsel review.

Done reading? Get your free audit →