Legal · Terms of Service
Blossom Terms of Service
Version 0.1 — Last updated July 22, 2026
These Terms of Service (the “Terms”) are an agreement between Polymath HQ, Inc., a Delaware corporation based in New York and operating as Blossom (“Blossom,” “we,” “us,” or “our”), and the person or organization accepting them (“Customer,” “you,” or “your”). They govern access to Blossom’s paid and production services, websites, applications, AI agents, and related features (collectively, the “Services”).
By clicking to accept, signing an order, or using the Services, you agree to these Terms. If you accept for an organization, you represent that you have authority to bind it. The individual accepting for an organization is not personally liable merely because they accepted on its behalf.
1. Agreement and order of precedence
In short: These Terms form the base agreement. Data terms, order-specific terms, and the AUP apply alongside them.
The agreement includes these Terms, the Acceptable Use Policy (“AUP”), the Data Processing Addendum (“DPA”), and any order form or online order identifying the Services, fees, or subscription terms (an “Order”). If documents conflict, the DPA controls for processing personal data, an Order controls for its specific commercial and service terms, these Terms control next, and the AUP controls for use restrictions. A customer purchase order does not modify the agreement unless Blossom expressly signs it.
The free business-process Audit is governed by the Audit Terms, unless an Order expressly says otherwise.
2. Eligibility, territory, and accounts
In short: Blossom is a US business service for adults and authorized business users. Keep accounts accurate and secure.
The Services are offered for business use in the United States. You must be at least 18 years old and legally able to enter the agreement. You will provide accurate account information, designate authorized users, keep credentials confidential, use reasonable safeguards, and promptly notify Blossom of suspected unauthorized access. You are responsible for use of the Services through your accounts by your authorized users.
You may not share individual credentials, bypass access controls, or allow an account to be used by anyone whose access has been suspended. Blossom may rely on the authority of your account owners and administrators to manage users, permissions, agents, integrations, and account settings.
3. The Services
In short: Blossom provides configurable software and AI agents. Features may evolve, and previews may be less reliable.
Subject to the agreement, Blossom grants Customer a limited, non-exclusive, non-transferable right during the subscription term to access and use the Services for its internal business purposes. Blossom may improve or change the Services, but will not materially reduce the core functionality of a paid Service during its current subscription term without reasonable notice.
Features labeled beta, preview, experimental, or evaluation may be changed or discontinued at any time and are provided without service levels or commitments unless an Order says otherwise. Statements about round-the-clock operation, turnaround times, savings, consistency, or launch timing describe intended product capabilities and are not guarantees unless expressly included in an Order.
4. Agent authority and Customer control
In short: You choose what agents may do. Actions within that configured scope are treated as your actions, and Blossom is your limited technical agent for carrying them out.
Customer controls each agent’s instructions, permissions, connected systems, approval settings, recipients, and operating scope (the “Configured Scope”). Customer appoints Blossom as its authorized representative and limited technical agent solely to set up, operate, and maintain the Services and to transmit or perform actions within the Configured Scope. This appointment does not create a fiduciary, employment, partnership, brokerage, or general agency relationship and does not authorize Blossom to make business or legal judgments for Customer.
As between the parties, communications and actions an agent takes within the Configured Scope at Customer’s direction are Customer’s communications and actions. Customer is responsible for reviewing the Configured Scope, approvals, recipients, and consequences of those actions. Customer is not responsible under this allocation for behavior outside the Configured Scope to the extent caused solely by a defect in the Blossom platform and not by Customer Data, instructions, configuration, unauthorized access attributable to Customer, or a third-party service.
Customer may pause an agent, change permissions, disconnect a service, or revoke credentials using available controls. Customer will promptly do so if it knows or reasonably suspects an agent is operating improperly.
5. Activity records and human oversight
In short: Blossom records agent actions executed through the Services, and you must use those records and appropriate human review.
Blossom will maintain activity records for agent actions executed through the Services and make relevant records available through the product or a reasonable export method. Records may depend on data returned by third-party services and do not capture conduct outside Blossom’s execution path. Customer is responsible for monitoring agents, reviewing higher-risk actions, maintaining any records the law requires, and escalating matters to qualified people.
Blossom may provide approval, disclosure, suppression, quiet-hours, or other guardrails. Customer will not disable, evade, or misconfigure a guardrail in violation of law or the AUP. Guardrails reduce risk but do not replace Customer’s legal review, consent records, or oversight.
6. Customer Data
In short: Your data remains yours. You give Blossom only the rights needed to provide, secure, and support the Services.
“Customer Data” means information, content, instructions, files, communications, recordings, credentials, and other material submitted to or processed through the Services by or for Customer, including data obtained from systems Customer connects. As between the parties, Customer retains all rights in Customer Data. Customer grants Blossom and its subprocessors a non-exclusive, worldwide, limited license to host, copy, transmit, display, modify, and otherwise process Customer Data only as needed to provide, secure, maintain, and support the Services, comply with law, and enforce the agreement.
Customer represents and warrants that it has all rights, notices, permissions, lawful bases, and consents needed for Customer Data and Blossom’s processing under the agreement. Customer will not direct Blossom to process Customer Data in violation of law, a duty owed to another person, or the terms governing a connected service.
The DPA governs personal data processed by Blossom on Customer’s behalf. Blossom acts as a processor or service provider for that data; Customer determines the purposes and means of processing.
7. No outside AI-model training
In short: Blossom and its AI-model providers do not train outside AI models on Customer Data unless you first give revocable, account-specific consent for a clearly identified high-risk or new AI model.
Blossom will not use Customer Data to train, develop, or improve any AI model made available outside Customer’s account. Blossom contractually restricts its AI-model providers from using Customer Data to train, develop, or improve their models and requires provider retention restrictions appropriate to the service.
The only exception is for a high-risk or newly available AI model that cannot meet those restrictions. Blossom may enable such a model for Customer’s account only after giving Customer clear information about the provider, the data involved, the purpose, and the applicable training or retention terms, and obtaining Customer’s prior, affirmative, account-specific consent. Customer may revoke that consent at any time for future use. Revocation will stop new Customer Data from being sent to that model; it cannot reverse processing completed before revocation. Refusing or revoking consent will not enable the model, though the related optional feature may be unavailable.
8. Third-Party Services You Connect
In short: When you connect your own Gmail, Microsoft 365, Slack, Zoom, phone, notetaker, or other service, Blossom accesses it on your instruction under your agreement with that provider.
Customer may direct the Services to access or interact with third-party products, accounts, data sources, communications systems, banks, or other services that Customer obtains independently (“Customer-Connected Services”). Examples include Customer’s own Google Workspace or Gmail, Microsoft 365, Slack, Zoom, phone systems, notetakers, and services listed in Blossom’s connector directory.
Customer-Connected Services are not Blossom subprocessors merely because Customer connects them. Customer—not Blossom—chooses and contracts with those providers. Blossom accesses them on Customer’s instruction using permissions Customer supplies. Customer is responsible for:
- having authority to connect and use each service and its data;
- ensuring the connection and intended use comply with law and the provider’s terms;
- selecting least-privilege access where available;
- configuring, monitoring, and revoking access; and
- all third-party fees, availability, changes, suspensions, and acts or omissions.
Blossom does not control and is not responsible for a Customer-Connected Service. A provider may change or block an interface, revoke credentials, impose limits, or discontinue functionality, which may cause a Blossom feature to degrade or stop. Blossom may suspend an integration that creates a legal, security, or platform-policy risk.
Vendors Blossom itself hires to host, route, automate, or otherwise operate the Services—including operation of connections—are listed as subprocessors on the Subprocessor List.
9. Credentials and connection security
In short: Use authorized, least-privilege credentials. Blossom protects credentials it holds, but you remain responsible for granting and revoking access correctly.
Customer authorizes Blossom to use credentials, tokens, sessions, and connection information solely to operate the requested connection. Customer represents that this access is authorized and consistent with the third party’s terms. Blossom will use OAuth where supported and appropriate, apply scoped access where available, and protect credentials and secrets it stores with encryption and access controls described in the Security Overview. Some connection providers identified on the Subprocessor List may hold Customer OAuth tokens on Blossom’s behalf.
Customer must not provide personal credentials where an approved business or delegated-access method is required. Customer will promptly rotate or revoke credentials affected by a security incident, personnel change, or loss of authorization.
10. AI outputs
In short: AI output can be inaccurate. You must evaluate it and use human review before acting on or sharing it.
“Output” means content, recommendations, classifications, decisions, or other material generated by an AI-enabled feature. Output may contain material inaccuracies, omissions, bias, or content that does not reflect current facts. Customer is responsible for evaluating whether Output is appropriate for its use—including where human or qualified-professional review is appropriate—before using, sharing, or acting on it. Customer must not represent that Output is human-generated where disclosure is required or where doing so would mislead a person.
Subject to the agreement and applicable law, Blossom assigns to Customer any rights Blossom may have in Output generated specifically for Customer. Because machine-generated content may not qualify for intellectual-property protection and similar output may be generated for others, Blossom does not promise exclusivity, ownership, validity, or non-infringement of Output.
BLOSSOM MAKES NO REPRESENTATION OR WARRANTY AND PROVIDES NO INDEMNITY WITH RESPECT TO OUTPUT.
11. Communications, calls, and recordings
In short: You are the sender or call-maker and must have consent for every recipient. Blossom pairs that responsibility with built-in compliance guardrails.
For communications initiated or controlled by Customer through the Services, Customer is the sender, initiator, or call-maker to the extent provided by law. Customer represents and warrants that it has each recipient’s valid consent and all other authority required for the channel, content, purpose, and time of contact, including prior express written consent where required for marketing calls or messages using an artificial or prerecorded voice. Customer will maintain consent and opt-out records, identify itself accurately, make required AI and recording disclosures, and comply with the TCPA, Telemarketing Sales Rule, CAN-SPAM Act, state call-recording and telemarketing laws, carrier requirements, and other applicable rules.
Customer will honor revocation made through any reasonable means and across applicable channels. Blossom will maintain available suppression and opt-out controls, support cross-channel revocation, and configure supported quiet-hours controls. Customer must not disable or bypass them. Blossom will process supported revocations within 10 business days, but Customer remains responsible for immediately stopping communications where law requires faster action or the request is received outside Blossom.
An AI agent must identify itself as automated or AI-assisted at the beginning of a call or chat where required by law, provider policy, or the AUP. If a communication will be recorded or transcribed, Customer must provide notice and obtain consent before recording where required, including in all-party-consent jurisdictions.
The parties acknowledge that statutory or regulatory responsibility may attach to more than one participant and cannot always be reassigned by contract. This section allocates responsibility between the parties without limiting rights of regulators, carriers, or recipients.
12. iMessage and other messaging channels
In short: iMessage follows the same consent rules as every channel, and Apple may limit or end the functionality.
Customer’s obligations for consent, identification, opt-outs, quiet hours, content, and records apply to iMessage and every other messaging channel. iMessage functionality depends on Apple-controlled devices, software, policies, and infrastructure. Apple does not provide a general sanctioned outbound iMessage API, and Apple may change or restrict access at any time. Blossom does not guarantee blue-bubble status, delivery, availability, message classification, or continued iMessage support and may modify, suspend, or discontinue the channel if required by Apple, a provider, law, or security considerations.
13. Payments, card information, and check deposit
In short: You remain the merchant and control the money. Card details must stay in the approved payment flow; you bear the banking and fraud risks of remote check deposit.
Customer is the merchant of record for transactions it conducts through the Services unless an Order expressly states otherwise. Customer is responsible for prices, refunds to its own customers, receipts, taxes, disputes, chargebacks, consumer disclosures, and compliance with payment-network and financial-services rules. Blossom’s fees, including any marketplace or application fee disclosed in an Order or transaction flow, do not make Blossom the seller of Customer’s goods or services or the custodian of Customer funds.
Payment-card numbers and security codes must not be entered into an AI chat, prompt, transcript, recording, or general Customer Data field. Customer must use the approved payment flow, such as a processor-hosted page or supported DTMF capture, so card data remains outside the AI pipeline.
If Customer authorizes an agent to assist with remote deposit capture (“RDC”) or delivery of check images, Customer represents and warrants that it owns or is authorized to deposit the item and that its bank agreement permits the capture method and any third-party technical assistance. Customer is solely responsible for endorsement, image quality, deposit limits, record retention and destruction, duplicate presentment, returned items, fraud, disputes, and compliance with its bank’s RDC terms and applicable law. Customer must review and approve a deposit before submission unless an Order expressly describes another control. Blossom does not accept, endorse, negotiate, hold, transmit funds for, or become a bank or money-services business by providing technical assistance. Blossom may suspend the feature if it identifies suspected fraud, duplicate presentment, or legal or bank-policy risk.
14. Acceptable use
In short: Use Blossom lawfully and safely. Higher-risk uses need stronger review and controls.
Customer and its users must comply with the AUP and upstream provider policies made available through the Services. Blossom may investigate suspected violations and suspend or restrict affected use when reasonably necessary to prevent harm, comply with law, protect the Services, or satisfy a provider requirement. Where practicable, Blossom will give notice and an opportunity to cure.
15. Fees, billing, taxes, and refunds
In short: Prices and billing terms appear in your Order. New paid subscriptions have a 30-day refund period unless the Order says otherwise.
Customer will pay the fees, usage charges, and applicable taxes stated in an Order or the checkout flow. Fees are in US dollars and are charged using the stated billing schedule. Except as expressly stated in the agreement, fees are non-cancelable and non-refundable. Overdue undisputed amounts may accrue interest at the lesser of 1.5% per month or the maximum lawful rate, and Blossom may suspend the affected Services after reasonable notice.
Unless an Order states different refund terms, Customer may cancel a new paid subscription within 30 days after its initial start date and request a refund of subscription fees paid for that period by contacting legal@blossom.fm. Usage-based charges, pass-through third-party costs, marketplace purchases, and renewals are excluded unless the checkout flow says otherwise or law requires a refund.
Customer is responsible for sales, use, value-added, withholding, and similar taxes, excluding taxes on Blossom’s net income. If Customer must withhold, it will provide valid documentation and, where lawful, pay amounts needed for Blossom to receive the fees stated in the Order.
16. Confidentiality
In short: Each side protects the other’s confidential information and uses it only for the agreement.
“Confidential Information” means nonpublic information disclosed by one party that is marked confidential or that a reasonable person would understand to be confidential, including Customer Data, credentials, product plans, security information, and pricing. The receiving party will use Confidential Information only to perform or receive the Services; protect it with at least reasonable care; and disclose it only to personnel, affiliates, advisers, and providers that need it and are bound to protect it.
Confidentiality duties do not apply to information the receiving party can document was lawfully known without restriction, becomes public without breach, is received lawfully from another source without a duty, or is independently developed. A party may disclose information when legally required, and will give advance notice where law permits and reasonable assistance at the disclosing party’s expense.
17. Intellectual property and feedback
In short: Blossom owns the Services; you own Customer Data. Voluntary feedback may be used freely.
Blossom and its licensors own the Services, software, models, designs, documentation, and all related intellectual-property rights, excluding Customer Data and Customer-specific Output addressed above. No rights are granted except those expressly stated. Customer may not copy, modify, sell, sublicense, reverse engineer, or create derivative works of the Services except to the extent law prohibits that restriction, nor use the Services to build a competing product through unauthorized extraction or benchmarking.
If Customer voluntarily provides feedback, Customer grants Blossom a perpetual, irrevocable, worldwide, royalty-free, sublicensable license to use and incorporate it without restriction or payment. This license does not cover Customer Data, branding, or Confidential Information merely because it accompanies feedback.
18. Privacy, security, and subprocessors
In short: The DPA governs Customer personal data, and the public Subprocessor List identifies the vendors Blossom engages.
Blossom will process Customer personal data under the DPA and maintain safeguards described in the Security Overview. Blossom may use the subprocessors listed on the Subprocessor List, subject to the notice and objection procedure there. Blossom’s Privacy Policy applies when Blossom acts as controller for website, lead, account-administration, and direct relationship information.
19. Suspension
In short: Blossom may suspend only as reasonably needed for security, legal, payment, provider, or serious misuse issues.
Blossom may suspend affected access immediately if reasonably necessary to prevent material harm, respond to a security incident, comply with law or a binding provider requirement, stop prohibited or fraudulent activity, or protect another customer. Blossom may also suspend for overdue undisputed fees after notice and a reasonable opportunity to cure. We will limit suspension to the affected account, user, integration, agent, or function where reasonably practicable and restore access after the issue is resolved.
20. Term, termination, and data return
In short: The agreement lasts for the subscription term. After it ends, export promptly; deletion follows the DPA and retention policy.
The agreement begins when Customer accepts it and continues until all Orders end. Subscriptions renew as stated in the Order. Either party may terminate for material breach if the breach is not cured within 30 days after written notice, or immediately if the breach cannot be cured. Either party may terminate if the other becomes insolvent or enters a bankruptcy proceeding not dismissed within 60 days. Customer may stop a month-to-month self-service subscription through the account or stated cancellation method.
Before termination or account deletion, Customer should export Customer Data using available tools. On request made before termination or within 30 days after it, Blossom will provide a reasonable standard export where technically available. Blossom will delete Customer Data within 30 days after account deletion, subject to the DPA, legal retention requirements, and limited backup cycles. Raw Scout artifacts are purged no later than 90 days after collection and may be purged earlier at the end of onboarding.
Accrued payment obligations and provisions that should by their nature survive will survive, including confidentiality, intellectual property, disclaimers, indemnities, liability limits, and dispute terms.
21. Warranties and disclaimers
In short: Blossom promises professional service delivery, but not perfect AI output, uninterrupted availability, or any particular business result.
Blossom warrants that it will provide paid Services in a professional and workmanlike manner. Customer’s exclusive remedy for breach of this warranty is for Blossom to reperform the affected Service or, if Blossom cannot do so within a reasonable period, refund prepaid fees for the affected Service covering the period after termination.
EXCEPT FOR THE EXPRESS WARRANTY ABOVE AND TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE SERVICES, OUTPUT, INTEGRATIONS, AND THIRD-PARTY SERVICES ARE PROVIDED “AS IS” AND “AS AVAILABLE.” BLOSSOM DISCLAIMS ALL IMPLIED, STATUTORY, AND OTHER WARRANTIES, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, ACCURACY, AND QUIET ENJOYMENT. BLOSSOM DOES NOT WARRANT THAT THE SERVICES OR OUTPUT WILL BE UNINTERRUPTED, ERROR-FREE, SECURE, COMPLETE, OR SUITABLE FOR A PARTICULAR DECISION; THAT AN AGENT WILL PRODUCE THE SAME RESULT ACROSS RUNS; OR THAT CUSTOMER WILL ACHIEVE A PARTICULAR SAVING, REVENUE, TIMELINE, OR OTHER OUTCOME.
22. Indemnification
In short: Each side covers defined third-party claims within its control. Customer covers its data, instructions, communications, payments, and misuse; Blossom covers the core Service’s IP—not AI Output.
Blossom will defend Customer against a third-party claim that the unmodified paid Services, when used as authorized, infringe a US patent, copyright, or trademark, and will pay damages and reasonable costs finally awarded or agreed in settlement. Blossom has no obligation for claims arising from Customer Data, Output, Customer instructions or configuration, combination with items not supplied by Blossom, modification by anyone other than Blossom, continued use after notice, or Customer-Connected Services. If a claim appears likely, Blossom may modify or replace the affected Service or terminate it and refund prepaid fees for the unused remainder of the affected term. This paragraph states Customer’s exclusive remedy for intellectual-property claims and does not provide any indemnity for Output.
Customer will defend Blossom and its affiliates and personnel against third-party claims arising from Customer Data; Customer’s instructions, Configured Scope, or agent actions within it; Customer’s breach of Sections 4, 6, 8–13, or the AUP; communications, calls, recordings, consents, or opt-outs; Customer’s goods, services, payments, check deposits, or merchant activity; or use of the Services in violation of law or another person’s rights. Customer will pay damages and reasonable costs finally awarded or agreed in settlement.
The indemnified party must promptly notify the indemnifying party, provide reasonable cooperation at the indemnifying party’s expense, and allow it to control the defense and settlement. The indemnifying party may not admit fault by or impose a non-monetary obligation on the indemnified party without consent, not to be unreasonably withheld.
23. Limitation of liability
In short: Neither side is liable for remote damages, and ordinary liability is capped at 12 months of fees, subject to specific exceptions.
TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY WILL BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, REVENUE, GOODWILL, OR BUSINESS OPPORTUNITY, EVEN IF ADVISED THEY WERE POSSIBLE.
EXCEPT FOR THE EXCLUDED CLAIMS BELOW, EACH PARTY’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THE AGREEMENT WILL NOT EXCEED THE FEES CUSTOMER PAID OR OWED FOR THE SERVICES GIVING RISE TO THE CLAIM DURING THE 12 MONTHS BEFORE THE FIRST EVENT GIVING RISE TO LIABILITY. For free Services, Blossom’s aggregate liability will not exceed US $100.
The cap and consequential-damages exclusion do not apply to Customer’s payment obligations; either party’s fraud, willful misconduct, or liability that law cannot limit; Customer’s infringement or misappropriation of Blossom’s intellectual property; or a party’s indemnification obligations. Liability arising from a party’s breach of confidentiality, the DPA, or security obligations is capped at two times the general cap. The parties agree these allocations are an essential basis of the bargain.
24. Governing law and disputes
In short: New York law and courts govern disputes.
The agreement is governed by New York law, without regard to conflict-of-law rules. The state and federal courts located in New York County, New York have exclusive jurisdiction over any dispute, and each party consents to personal jurisdiction and venue there. EACH PARTY WAIVES A JURY TRIAL TO THE EXTENT PERMITTED BY LAW. Before filing a claim, a party will give written notice and allow 30 days for good-faith business resolution, except where immediate injunctive relief is reasonably necessary.
25. General terms
In short: Standard contract rules apply, and neither side becomes the other’s partner or employee.
Neither party may assign the agreement without the other’s consent, except to an affiliate or in connection with a merger, reorganization, or sale of substantially all relevant assets, provided the assignee agrees to the agreement. Any other assignment is void. The parties are independent contractors. Except for Customer’s limited appointment in Section 4, the agreement creates no agency, partnership, joint venture, fiduciary, franchise, or employment relationship.
Neither party is liable for delay caused by events beyond its reasonable control, except payment obligations. Notices must be in writing. Blossom may send notices to Customer’s account email or through the Services; legal notices to Blossom must be sent to legal@blossom.fm. If a provision is unenforceable, it will be limited to the minimum necessary and the rest remains effective. A waiver must be in writing and is not continuing. The agreement is the entire agreement about its subject. Headings and “In short” summaries aid reading but do not change the operative terms.
26. Changes to these Terms
In short: Blossom will give 30 days’ advance notice before material changes take effect.
Blossom may update these Terms. We will provide at least 30 days’ advance notice of a material change by email, in-product notice, or prominent website notice, unless a faster change is required by law or needed to address an urgent security risk. Changes apply prospectively when they take effect. If Customer objects to a material change that materially and adversely affects an existing paid subscription, Customer may notify Blossom before the effective date and terminate the affected Service; Blossom will refund prepaid fees for the unused remainder of that Service. Continued use after the effective date constitutes acceptance.
27. Contact
In short: Legal notices and questions go to legal@blossom.fm.
Polymath HQ, Inc. d/b/a Blossom
New York, United States
Attention: Noah Lenz
legal@blossom.fm
Changelog
In short: This is the first working-draft version.
| Date | Version | Change |
|---|---|---|
| July 22, 2026 | 0.1 | Initial working draft for counsel review. |