Blossom

Legal · Privacy Policy

Blossom Privacy Policy

Version 0.1 — Last updated July 22, 2026

This Privacy Policy explains how Polymath HQ, Inc., a Delaware corporation based in New York and operating as Blossom (“Blossom,” “we,” “us,” or “our”), collects, uses, discloses, and retains personal information when we act as the business or controller. It applies to our website, marketing inquiries, account administration, billing relationships, and direct support interactions.

1. Scope

In short: This policy covers information Blossom handles for its own business. Customer workspace and connected-system data is governed by customer agreements and the DPA.

This policy does not apply to personal information that Blossom processes on behalf of a business customer through its workspace, agents, Audit, or connected systems. For that information, the customer decides why and how the information is processed, and Blossom acts as its processor or service provider under the Data Processing Addendum. If you are an employee, customer, or other person whose information was submitted by a Blossom customer, please direct privacy requests to that customer. We will assist the customer as required by our agreement and applicable law.

This policy also does not govern third-party websites or services that you choose to connect to Blossom or visit through a link. Their own privacy notices apply.

2. Customer Data and AI model training

In short: Even though Customer Data is outside this policy’s controller scope, Blossom and its AI-model providers do not use it to train outside AI models unless the Customer first opts into a disclosed, account-specific exception.

Blossom does not use Customer Data to train, develop, or improve an AI model made available outside the Customer’s account, and contractually restricts its AI-model providers from doing so. If a high-risk or new AI model cannot meet those restrictions, Blossom will not send Customer Data to it unless the Customer first receives clear information about the provider, data involved, purpose, and applicable training or retention terms and gives affirmative, account-specific consent. The Customer may revoke that consent at any time for future use. The Data Processing Addendum and Terms of Service govern this processing and the exception mechanism.

3. Information we collect

In short: We collect the information you give us, basic account and transaction records, support information, and limited technical data needed to run and secure the service.

CategoryExamplesMain sources
Contact and identity informationName, work email, phone number, company, title, profile picture, and organization membershipYou; your organization; WorkOS
Inquiry and marketing informationEmail, industry, referral source, questions submitted through our site, and any phone number or optional email included with a questionYou; your organization
Account and authentication informationUser and organization identifiers, login and session records, role, team membership, and authentication data managed by WorkOSYou; your organization; WorkOS; our systems
Commercial and billing informationPlan, subscription status, transaction amounts, billing contact, and tax or invoice records. Payment-card details are collected by Stripe rather than placed in Blossom’s AI pipelineYou; your organization; Stripe
Support and communications informationMessages with our team, support requests, feedback, and, when you choose to provide them, screen recordings or attachmentsYou; Birdie; our support systems
Device, usage, and security informationIP address, browser or device type, request and event timestamps, authentication events, and logs needed to operate, troubleshoot, and protect the serviceYour browser or device; our hosting, authentication, and security providers
InferencesBasic conclusions drawn from inquiry, account, or usage information to route a request, provide support, prevent abuse, or understand which Blossom service may be relevantInformation listed above

Some account-authentication information, such as credentials or account-access data, may be treated as sensitive personal information under state law. Blossom uses it only to authenticate users, secure accounts, prevent fraud, and provide the requested service. Blossom does not use or disclose sensitive personal information to infer characteristics about a person.

4. How we use information

In short: We use personal information to respond, provide and secure Blossom, administer accounts and billing, meet legal duties, and improve our direct relationship with you.

We use the categories above to:

  • respond to questions, schedule and perform an Audit, and provide requested information;
  • create and administer accounts, organizations, teams, roles, authentication, and support;
  • provide, maintain, troubleshoot, and secure the website and services;
  • process subscriptions, payments, invoices, refunds, and tax records;
  • send transactional, service, security, and legal notices;
  • send marketing communications where permitted by law and honor opt-outs;
  • detect, investigate, and prevent fraud, abuse, security incidents, and violations of our terms;
  • analyze and improve our website, support, and account experience using first-party operational information; and
  • comply with law, enforce agreements, and establish, exercise, or defend legal claims.

Blossom does not use controller-scope personal information to make decisions that produce legal or similarly significant effects concerning a consumer. If that practice changes, we will update this policy and provide rights required by applicable law.

5. How we disclose information

In short: We disclose information to vendors that help us operate, for transactions or legal reasons, and at your direction. We do not sell it or share it for cross-context behavioral advertising.

We may disclose personal information to:

  • Infrastructure and account providers that host the service, authenticate users, deliver email, and support operations;
  • Payment providers that process subscriptions, transactions, payouts, invoices, and tax-related information;
  • Support and business-service providers that help us respond to inquiries, enrich company information entered during an Audit, and provide customer support;
  • Professional advisers and authorities when reasonably necessary for legal, tax, accounting, compliance, security, or claims purposes;
  • Transaction counterparties in connection with a proposed or completed financing, merger, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality protections; and
  • Others at your direction or with your consent.

Blossom does not sell personal information. Blossom does not share personal information for cross-context behavioral advertising or process it for targeted advertising. We do not disclose mobile opt-in data or consent records to third parties for their own marketing. Service providers may receive that information only as necessary to provide communications for Blossom and must use it for that purpose.

The Subprocessor List identifies vendors Blossom uses to process customer data on a customer’s behalf. It is broader than the controller-side vendor categories in this section because it covers operation of the full Blossom service.

6. Cookies and browser signals

In short: Blossom currently uses essential and first-party functional technologies, not ad pixels. We honor Global Privacy Control signals.

Our Cookie Policy describes the cookies and similar technologies used on our site. We do not currently use advertising pixels or third-party behavioral advertising cookies. Where a recognized Global Privacy Control (GPC) signal applies, we treat it as a valid request to opt out of sale, sharing, or targeted advertising—even though we do not currently engage in those practices.

7. Data retention

In short: Account information follows the account, legal records last as law requires, and leads remain until deletion is requested.

InformationRetention approach
Account, organization, profile, and direct-support recordsKept while the account is active and deleted within 30 days after account deletion, unless a narrower period applies or law requires retention
Marketing leads and questionsKept until the person asks us to delete them, subject to any limited legal need to retain a suppression or request record
Billing and tax recordsKept for as long as applicable law requires
Security, fraud, and legal recordsKept only as long as reasonably necessary to protect the service, comply with law, resolve disputes, and enforce agreements, based on the record’s sensitivity, purpose, and applicable limitation periods

Deletion may take additional time from encrypted backups maintained on a limited, access-restricted cycle. During that period, backup data is isolated from ordinary use and retained only for recovery, security, and legal purposes.

Customer workspace and connected-system data—including raw Scout Audit artifacts—is outside this policy’s controller scope. Its retention and deletion terms appear in the Data Processing Addendum and Audit Terms.

8. Data security

In short: We use administrative, technical, and organizational safeguards, but no service can promise perfect security.

We use safeguards designed to protect personal information in light of its sensitivity and the risks of processing. These include access controls, encryption in transit, encrypted storage for certain credentials and secrets, tenant and role controls, logging, vendor review, and incident-response practices. See our Security Overview for more detail. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9. Your privacy rights

In short: Depending on where you live, you may ask to access, correct, delete, or receive your information, and to opt out of certain uses. We apply a US national baseline rather than separate state appendices.

Subject to applicable exceptions, you may request that Blossom:

  • confirm whether we process your personal information and provide access to it;
  • correct inaccurate personal information;
  • delete personal information;
  • provide a portable copy of personal information you provided;
  • identify categories of information collected, sources, purposes, and recipient categories, including information collected more than 12 months ago where required;
  • opt you out of targeted advertising, sale, or profiling in furtherance of decisions producing legal or similarly significant effects; and
  • limit certain uses of sensitive personal information.

Blossom does not currently sell personal information, share it for cross-context behavioral advertising, use it for targeted advertising, or profile consumers for decisions producing legal or similarly significant effects.

To exercise a right, email legal@blossom.fm with the subject “Privacy Request” and describe your request. You may also use an authorized agent where law permits. We may verify your identity and authority by matching information associated with your request or asking for additional information. We will respond within the period required by applicable law and will explain any denial. You may appeal a denial by replying with the subject “Privacy Appeal.” If the appeal is denied, we will provide information about how to contact the appropriate regulator where required.

We will not discriminate against you for exercising a privacy right. We may retain a minimal record of your request and, if you opt out of marketing, your contact information on a suppression list so we can honor the choice.

10. Communications choices

In short: You can unsubscribe from marketing and revoke consent through reasonable means; important service messages may continue.

You may unsubscribe from marketing email using the link in the message or by emailing us. You may revoke consent to marketing calls or messages by any reasonable method communicated in the message, including commonly recognized opt-out words where supported, or by contacting legal@blossom.fm. We will honor a valid revocation across applicable channels within 10 business days. We may still send non-marketing communications needed for an account, transaction, security issue, or legal notice.

11. Children

In short: Blossom is a business service and is not directed to children.

Blossom is not directed to children under 13, and we do not knowingly collect their personal information. The service is available only to people who are at least 18 years old. If you believe a child has provided personal information to us, contact us so we can investigate and delete it where appropriate.

12. United States operations

In short: Blossom operates from the United States, and information may be processed there.

Blossom is based in New York and provides its service in the United States. If information is submitted from another country, it may be transferred to, stored in, and processed in the United States, where laws may differ from those in your country. Customer-data transfer terms, where applicable, are addressed in the Data Processing Addendum.

13. Changes to this policy

In short: We will post updates and give 30 days’ advance notice of material changes unless law or urgent security needs require faster action.

We may update this policy to reflect changes in our practices, services, or legal obligations. We will give at least 30 days’ advance notice of material changes by email, in-product notice, or a prominent website notice, unless a faster update is required by law or needed to address an urgent security risk. The “Last updated” date shows when the current version was issued.

14. Contact us

In short: Privacy questions and requests go to legal@blossom.fm.

Polymath HQ, Inc. d/b/a Blossom
New York, United States
Attention: Noah Lenz
legal@blossom.fm

Changelog

In short: This is the first working-draft version.

DateVersionChange
July 22, 20260.1Initial working draft for counsel review.