Trust
Most software asks you to trust it. This section is the opposite: every claim Lolly makes about your content, your data and its own behaviour is written down here with the mechanism that enforces it, so you can check rather than believe.
Three questions bring people here. Start wherever yours sits.
Where did this content come from?
Every image, PDF and video Lolly renders carries Content Credentials by default - a signed record of what made it, from what, and when. When a file arrives with a history already attached, Lolly preserves it rather than flattening it, so the chain stays intact through an edit.
- Content Credentials - what gets signed, what the signature proves, and who the signer is.
- Content Credentials - Engineering - the C2PA implementation itself: manifests, ingredients, action histories, formats.
- Our AI Stance - where AI is welcome, where it is not, and why AI-generated content declares itself.
Can I check that for myself?
You can, and you should - the point of provenance is that it does not need our word.
- Verify It Yourself - walk the claims on this site against a real export, step by step.
- Security & Verification - how the code is built, signed and checked.
- Threat Model - what Lolly defends against, and what it explicitly does not.
- Parser Inventory - every format Lolly parses, because parsers are where untrusted input meets your device.
- Server Surface - the complete list of what a server ever sees.
What happens to my data?
Lolly renders on your device. That is not a privacy posture bolted on afterwards - it is the architecture, and it is why most of the usual questions have short answers.
- Privacy Policy - what is collected, what is not, and what leaves your device.
- Data Transfer - moving your work in and out, with nothing held hostage.
- Inclusive Design - who the software is built to work for.
If you find a place where these pages and the code disagree, the code is the bug - and the repository is public so you can prove it either way.