The trade we never agreed to

Nobody sat us down and offered us the deal. It arrived one tool at a time, each step reasonable on its own, until the normal way to resize an image was to send it to a company none of us have met.

This page is about that accumulation. Not about villains, because most of it was built by people making sensible decisions inside incentives that pointed one way. The incentives are the problem, and they are the thing worth naming.

We did this easily

  • We uploaded a logo to a free converter, waited through an ad, and downloaded a file we hoped was the same picture.
  • We went back for artwork from eighteen months ago and found it behind a login for a plan the team had stopped paying for. The artwork was ours. The file was not reachable.
  • We accepted cookies we did not read, on a site we visited once, to do something that took eleven seconds.
  • We sent a near-final campaign to a colleague, who sent it onward, and the version everyone uses now is one nobody can point back to.
  • We clicked "not now" on the same upsell for a year.

The cost

  • Our content became the price. A tool that runs on someone else's server has to be paid for, so the bill arrives as a subscription, an ad, a data broker or a training corpus. The upload was never technically necessary for resizing a picture. Browsers have done that locally for years.
  • Our files became leverage. Work kept in a format only one program opens is leverage over the person who made it, and leverage that expires with a card is not a partnership.
  • Our consent became paperwork. Twelve toggles and a forty-page policy do not produce informed agreement. They produce legal cover, and one more task standing between us and the work.
  • Our proof went missing. For most of the last decade a file carried no reliable record of where it came from. That was survivable while making a convincing image still took a studio. It is not survivable now.

None of it was carelessness. Each step was the reasonable one available at the time, and the incentives underneath were pointing the same way for everyone.

The old way and the new way

The usual wayHere
FrictionUpload, queue, sign in, dismiss the upsell, download something you hope is rightOpen a link and work. No account, no upload, no waiting on a stranger's server
RiskYour file rests on someone else's disk, under their retention policy and their breach exposureThe file never leaves your device, so there is no second copy to leak
QualitySilently re-encoded, resolution capped on the free tier, a watermark you pay to removeReal vector out, print-ready colour, the same render on every device, nothing withheld
TrustA policy you have to believe, rewritable at any time without telling youAn architecture you can check, and a signed credential travelling inside every export
EthicsYour work becomes training data or an ad profile by default, and consent is a wall you click throughNothing is collected, so nothing can be repurposed. AI declares itself, and access needs are settings rather than requests

Each row is a claim you can test rather than a slogan, which is what the rest of this section is for.

Trust what you can verify

Every one of those has a fix that is architectural, not a promise in a policy document. The difference matters: a promise is a thing a company can change on a Tuesday, and an architecture is a thing you can check.

What this is not

It is not a claim that everyone doing it the other way acts in bad faith. Server-side software is a legitimate way to build things, and plenty of it is made carefully by people who would rather not be collecting what they collect.

It is not a claim that Lolly does everything those tools do. It does a narrower set of things without the trade.

And it is not a request for your trust. Trust is the thing we are trying to make unnecessary. Everything above is checkable, the code is public, and the Threat Model is honest about the limits. If the page and the code ever disagree, the code is the bug.