Skip to main content

Trust & Security

Last updated: June 18, 2026

This page is maintained by ALL BEST MUSIC & MEDIA ("ABM") to answer common security and privacy questions about the abm.to platform. It is app-owned editable content and is not a certification or independent audit. ABM is built on the Lovable Cloud platform; some controls below are provided by that platform and some are configured and operated by ABM.

Accounts & authentication

  • Sign-in is available via email & password and Google.
  • Passwords are handled by the managed authentication service and are never stored in our application database.
  • Privileged actions (artist approvals, deletions, payouts) are restricted to administrator accounts and verified server-side.

Access control

Application data is stored in a managed Postgres database with row-level security enabled. Access policies are scoped to the signed-in user and their role (fan, artist, blogger, interviewer, business, admin). Sensitive columns such as invitation tokens and payout identifiers are not readable by client roles and are only accessed by trusted server endpoints.

Data in transit & at rest

All traffic to abm.to is served over HTTPS. Data at rest is stored in managed infrastructure provided by the Lovable Cloud platform, which handles disk-level encryption and backups for the database and file storage layers.

Data we collect

  • Account information you provide (email, display name, role-specific application details).
  • Content you publish (releases, posts, interviews, events, broadcasts).
  • Subscription and payout records required to operate memberships and pay artists.
  • Basic operational logs (sign-in events, email delivery state, moderation reports).

Subprocessors & integrations

ABM relies on a small number of trusted providers to operate the service:

  • Lovable Cloud — application hosting, database, file storage, and authentication.
  • Stripe — payment processing for fan memberships, paid invites, and artist payouts. Card details are entered directly with Stripe and are not stored by ABM.
  • Brevo — transactional email delivery (account, application, and notification emails).
  • ACRCloud — audio fingerprinting for copyright tooling.

Retention & deletion

You can request deletion of your account and associated personal data by contacting us at the address below. Some records (for example payout history, tax-relevant transactions, and moderation actions) may be retained for as long as required to meet legal and operational obligations.

Email & communication

Transactional emails (sign-in, applications, invites, payment receipts) are sent from e.abm.to. Marketing-style broadcasts include an unsubscribe link; transactional emails do not because they relate to account activity you initiated.

Reporting a security issue

If you believe you have found a security vulnerability, please email Management@e.abm.to with details and steps to reproduce. Please do not publicly disclose the issue until we have had a reasonable opportunity to investigate and respond.

Shared responsibility

Security is shared. ABM operates the application and configures platform controls; the Lovable Cloud platform operates the underlying infrastructure; and account holders are responsible for keeping their credentials safe, using a strong unique password, and only sharing invite links with people they intend to grant access to.

Changes & contact

This page may be updated as the service evolves. For questions about this page or about how your data is handled, contact Management@e.abm.to. For the legal terms governing use of the service, see our Terms of Service.