Trust & Security
Last updated: June 18, 2026
This page is maintained by ALL BEST MUSIC & MEDIA ("ABM") to answer common security and privacy questions about the abm.to platform. It is app-owned editable content and is not a certification or independent audit. ABM is built on the Lovable Cloud platform; some controls below are provided by that platform and some are configured and operated by ABM.
Accounts & authentication
- Sign-in is available via email & password and Google.
- Passwords are handled by the managed authentication service and are never stored in our application database.
- Privileged actions (artist approvals, deletions, payouts) are restricted to administrator accounts and verified server-side.
Access control
Application data is stored in a managed Postgres database with row-level security enabled. Access policies are scoped to the signed-in user and their role (fan, artist, blogger, interviewer, business, admin). Sensitive columns such as invitation tokens and payout identifiers are not readable by client roles and are only accessed by trusted server endpoints.
Data in transit & at rest
All traffic to abm.to is served over HTTPS. Data at rest is stored in managed infrastructure provided by the Lovable Cloud platform, which handles disk-level encryption and backups for the database and file storage layers.
Data we collect
- Account information you provide (email, display name, role-specific application details).
- Content you publish (releases, posts, interviews, events, broadcasts).
- Subscription and payout records required to operate memberships and pay artists.
- Basic operational logs (sign-in events, email delivery state, moderation reports).
Subprocessors & integrations
ABM relies on a small number of trusted providers to operate the service:
- Lovable Cloud — application hosting, database, file storage, and authentication.
- Stripe — payment processing for fan memberships, paid invites, and artist payouts. Card details are entered directly with Stripe and are not stored by ABM.
- Brevo — transactional email delivery (account, application, and notification emails).
- ACRCloud — audio fingerprinting for copyright tooling.
Retention & deletion
You can request deletion of your account and associated personal data by contacting us at the address below. Some records (for example payout history, tax-relevant transactions, and moderation actions) may be retained for as long as required to meet legal and operational obligations.
Email & communication
Transactional emails (sign-in, applications, invites, payment receipts) are sent from e.abm.to. Marketing-style broadcasts include an unsubscribe link; transactional emails do not because they relate to account activity you initiated.
Reporting a security issue
If you believe you have found a security vulnerability, please email Management@e.abm.to with details and steps to reproduce. Please do not publicly disclose the issue until we have had a reasonable opportunity to investigate and respond.
Shared responsibility
Security is shared. ABM operates the application and configures platform controls; the Lovable Cloud platform operates the underlying infrastructure; and account holders are responsible for keeping their credentials safe, using a strong unique password, and only sharing invite links with people they intend to grant access to.
Changes & contact
This page may be updated as the service evolves. For questions about this page or about how your data is handled, contact Management@e.abm.to. For the legal terms governing use of the service, see our Terms of Service.