Blossom

Legal · Acceptable Use Policy

Blossom Acceptable Use Policy

Version 0.1 — Last updated July 22, 2026

This Acceptable Use Policy (“AUP”) applies to all use of Blossom’s services and forms part of the Terms of Service. “Blossom” means Polymath HQ, Inc. d/b/a Blossom. Capitalized terms not defined here have the meanings in the Terms.

1. Universal standards

In short: Use Blossom lawfully, honestly, safely, and only with data, systems, and people you are authorized to reach.

You may not use the Services to:

  • violate law, regulation, court order, sanctions, or another person’s rights;
  • facilitate fraud, deception, phishing, malware, credential theft, unauthorized surveillance, or evasion of security controls;
  • access an account, system, network, data source, or API without authorization, or contrary to the applicable provider’s terms;
  • scrape, reverse engineer, or automate a third-party service where you lack permission or where the method violates its terms;
  • impersonate a person or organization, misrepresent an agent as human, or conceal sponsorship or identity where disclosure is required;
  • harass, threaten, exploit, discriminate against, or cause physical, financial, reputational, or emotional harm;
  • generate or distribute child sexual abuse material, non-consensual intimate imagery, sexual exploitation content, or content that facilitates abuse of a minor;
  • facilitate terrorism, violent extremism, human trafficking, illegal weapons, or instructions intended to cause serious harm;
  • infringe intellectual-property, privacy, publicity, confidentiality, or contractual rights;
  • introduce malicious code, overload the Services, bypass rate or usage limits, probe without authorization, or interfere with another customer;
  • use Output without appropriate review where an error could materially affect a person; or
  • disable or evade Blossom’s required approval, consent, disclosure, suppression, safety, logging, or security controls.

You must promptly stop an agent or workflow that is behaving unlawfully, unsafely, deceptively, or outside its Configured Scope and notify Blossom where the issue may affect the platform or other users.

2. Communications and outreach

In short: No unsolicited calls or messages. Have valid permission for every person, disclose AI where required, and honor every opt-out.

You may use Blossom for calls, email, SMS, iMessage, chat, or other outreach only when you:

  • have documented, valid consent or another lawful basis for each recipient, channel, purpose, and time of contact;
  • obtain prior express written consent where required for marketing calls or messages that use an artificial or prerecorded voice;
  • identify the business responsible for the communication and make required artificial-intelligence disclosures at the beginning of a call or chat;
  • give any notice and obtain any consent required before recording or transcribing, including in all-party-consent jurisdictions;
  • comply with calling-hour, do-not-call, campaign-registration, sender-identification, caller-ID, and carrier rules;
  • include legally required unsubscribe or opt-out instructions;
  • treat any reasonable revocation method as valid, including recognized words such as STOP, QUIT, END, REVOKE, OPT OUT, CANCEL, or UNSUBSCRIBE where supported;
  • honor revocation across applicable channels and no later than 10 business days after receipt, or sooner where law requires;
  • maintain consent, disclosure, opt-out, and suppression records; and
  • keep Blossom’s disclosure, quiet-hours, suppression, and opt-out controls enabled and correctly configured.

You may not send communications to purchased, scraped, or harvested lists without independently verified permission for the specific outreach. You may not use the Services for messaging campaigns involving SHAFT content—sex, hate, alcohol, firearms, or tobacco (including unlawful or restricted cannabis promotion)—or other carrier-prohibited categories.

You must not use Blossom to place calls to 911, emergency numbers, public-safety answering points, crisis hotlines, or any service where delay or failure could endanger a person. Blossom is not an emergency communications service.

These rules apply equally to iMessage. You may not claim or imply that Apple sponsors, authorizes, or guarantees the channel.

3. High-impact and regulated decisions

In short: AI may assist, but qualified people must review decisions in legal, health, finance, employment, housing, education, insurance, and similar high-impact areas.

You may not use the Services to make a final decision that determines a person’s eligibility, access, terms, or selection for employment, housing, education, credit, insurance, healthcare, legal services, government benefits, or another essential opportunity without meaningful review by a qualified person and all notices, explanations, assessments, testing, appeals, and human-review rights required by law.

You may not:

  • practice law, medicine, accounting, investment advising, or another licensed profession without appropriately licensed oversight;
  • make a medical diagnosis, direct clinical treatment, or handle a medical emergency;
  • make a fully automated decision based on highly sensitive data or protected characteristics where prohibited;
  • unlawfully discriminate or use proxies intended to evade anti-discrimination rules;
  • present Output as definitive professional advice; or
  • deny a person a legally required opportunity to contest or obtain human review.

For consumer-facing AI in these areas, clearly disclose that the person is interacting with an AI system and provide a practical path to a human where appropriate or required.

4. Health and sensitive data

In short: Minimize sensitive data, use it only with authority, and do not infer or sell health information.

You may submit health, biometric, precise-location, financial, credential, recording, or other sensitive data only when the Agreement permits it, you have a lawful basis and necessary consent, and you have configured appropriate access and retention controls. Do not use Blossom to sell consumer health data, infer health status for advertising, or collect sensitive data beyond what is reasonably necessary for the approved purpose.

Unless Blossom signs an agreement expressly authorizing a regulated use, the Services are not offered as a substitute for a legally required specialized environment, licensed professional, emergency system, or regulated recordkeeping system.

5. Government and civic uses

In short: No deceptive civic activity or unsupervised government filings. An authorized person must review every submission.

You may not use the Services for voter suppression, deceptive election content, false official communications, unauthorized lobbying disclosures, or impersonation of a government official. Any tax, licensing, benefits, immigration, corporate, court, procurement, regulatory, or other government filing must be reviewed and affirmatively approved by a person with authority to submit it. You remain responsible for signatures, attestations, deadlines, fees, evidence, and professional advice.

6. Payments and financial activity

In short: Keep card numbers out of AI conversations, and require human approval and bank authorization for check deposits.

Do not enter or solicit full payment-card numbers, security codes, PINs, or bank-login credentials through an AI conversation, prompt, transcript, or ordinary Customer Data field. Use only Blossom’s approved processor-hosted or supported DTMF payment flow.

Remote check-deposit assistance may be used only when your bank agreement permits it, an authorized person reviews and approves the deposit, and you comply with endorsement, image, retention, destruction, duplicate-presentment, fraud, and other bank requirements. You may not use Blossom to move, launder, conceal, or misappropriate funds; cash checks without authority; evade financial controls; or provide unlicensed money transmission or financial services.

7. Credentials, connectors, and third-party systems

In short: Connect only systems you control or are authorized to access, use least privilege, and follow the provider’s terms.

You must:

  • use authorized business, delegated, or OAuth access methods where available;
  • grant only the permissions reasonably needed for the workflow;
  • comply with the connected provider’s terms, technical restrictions, and acceptable-use rules;
  • avoid personal or shared credentials where a proper delegated method is required;
  • promptly rotate or revoke credentials when access ends or may be compromised; and
  • stop using a connection if the provider withdraws permission or the legal basis ends.

You may not direct Blossom to defeat CAPTCHAs, access restrictions, platform controls, or authentication requirements without express authorization from the system owner.

8. Model and provider rules

In short: Uses sent to an upstream model or platform must also follow that provider’s applicable safety rules.

Use of certain models, channels, or integration providers may be subject to additional provider policies made available in the product or documentation. You must comply with those policies. Blossom may block a prompt, Output, action, model, channel, or integration when reasonably necessary to satisfy a binding provider policy or prevent harm.

9. Enforcement and reporting

In short: Blossom may investigate and limit affected use, with notice and a chance to cure when practical.

Blossom may investigate suspected violations, preserve relevant records, remove or block content, limit an agent or integration, or suspend affected Services. Where practicable and safe, Blossom will notify you, explain the basis, and allow a reasonable opportunity to cure. Blossom may act immediately for illegal activity, material security risk, imminent harm, fraud, repeated violations, or a binding legal or provider requirement.

To report suspected misuse, email legal@blossom.fm. Blossom may cooperate with lawful requests from authorities and may notify affected people or providers where permitted and reasonably necessary.

10. Changes

In short: Material changes receive 30 days’ advance notice unless urgent law or safety needs require faster action.

Blossom may update this AUP. We will give at least 30 days’ advance notice of a material change by email, in-product notice, or a prominent website notice, unless a faster update is required by law, a provider, or an urgent security or safety risk. The “Last updated” date identifies the current version.

Changelog

In short: This is the first working-draft version.

DateVersionChange
July 22, 20260.1Initial working draft for counsel review.