Most software asks you to trust it. This section is the opposite: every claim Lolly makes about your content, your data and its own behaviour is written down here with the mechanism that enforces it, so you can check rather than believe.
The internet is optional with Lolly: use it when it helps, never surrender control. A font you pick, a place you look up, a link you share - things happen online only because you asked. Nothing you make ever leaves your device without your control and informed consent, Nobody is listening in. Go offline and everything you have works. Freedom is sweet.
The receipts: the Privacy Policy names every request the app can ever make, and Verify It Yourself shows you how to check each one.
Where did this content come from?
The media Lolly renders carries Content Credentials by default - a signed record of what made it, from what and when. When a file arrives with a history already attached, Lolly preserves it rather than flattening it, so the chain stays intact through an edit.
- Content Credentials - what gets signed, what the signature proves and who the signer is.
- Content Credentials - Engineering - the C2PA implementation itself: manifests, ingredients, action histories, formats.
- Our AI Stance - where AI is welcome, where it is not and why AI-generated content declares itself.
Can I check that for myself?
You can, and you should - the point of provenance is that it does not need our word.
- Verify It Yourself - walk the claims on this site against a real export, step by step.
- Security & Verification - how the code is built, signed and checked.
- Threat Model - what Lolly defends against, and what it explicitly does not.
- Parser Inventory - every format Lolly parses, because parsers are where untrusted input meets your device.
- Server Surface - the complete list of what a server ever sees.
What happens to my data?
Lolly renders on your device. That is not a privacy posture bolted on afterwards - it is the architecture, and it is why most of the usual questions have short answers.
- Privacy Policy - what is collected, what is not and what leaves your device.
- Data Transfer - moving your work in and out, with nothing held hostage.
- Inclusive Design - who the software is built to work for.
The refusal
Nothing to sell you, nothing to take. Four commitments, stated once and checkable:
- Free, and it stays free. A version that has been released is licensed so it can never be taken back. The free Lolly always exists, whatever happens next - the exact mechanism is on How Lolly compares.
- Open source. Read it, run it, fork it, keep it. Nothing on this page needs to be believed: the code is public and the claims are checkable.
- Blind by design. Lolly reports nothing back. Nobody, the makers included, can see who runs it or what they make - see the Privacy Policy. A tool that cannot see you has nothing to sell about you.
- Your vote, visible. Your work never goes where you have no say. Anything that touches the internet happens because you chose it, at the moment you chose it, and the code that keeps that promise is open.
Why this is free
We built Lolly for ourselves. SUSE needed thousands of on-brand files, each with its name sealed inside, made without handing anything to outside services. So we built a tool that does all of it on the device, and released it as open source, like everything else we make. We keep maintaining it because we use it every day. There is no obligation: everything here works with or without us.
If you find a place where these pages and the code disagree, the code is the bug - and the repository is public so you can prove it either way.