{
  "slug": "molly",
  "category": "messengers",
  "name": "Molly",
  "description": "Independent fork of the Signal Android app that connects to the Signal network and adds database encryption with a passphrase, UnifiedPush notifications and a Molly-FOSS build without proprietary Google components.",
  "website": "https://molly.im",
  "source": "https://github.com/mollyim/mollyim-android",
  "license": "AGPL-3.0",
  "platforms": [
    "android"
  ],
  "jurisdiction": null,
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "B",
  "score": 78,
  "coverage": 100,
  "summary": "Molly scores 78 out of 100 (grade B) on the messengers criteria. It meets 5 of 8 criteria: open source, no trackers or telemetry, no ads or data sales, end-to-end encrypted by default and metadata protection. It partly meets no phone number needed. It does not meet independent audit and decentralized.",
  "url": "https://privacyratings.com/messengers/molly/",
  "markdown": "https://privacyratings.com/messengers/molly/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://github.com/mollyim/mollyim-android/blob/main/LICENSE",
      "note": "AGPL-3.0, and it uses the open-source Signal server."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://github.com/mollyim/mollyim-android",
      "note": "No trackers or analytics; the Molly-FOSS build also removes proprietary Google components such as FCM and Google Maps."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://opencollective.com/mollyim",
      "note": "Free software with no ads, funded by donations through Open Collective."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No independent audit is published."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "e2ee_default": {
      "title": "End-to-end encrypted by default",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://signal.org/docs/",
      "note": "All messages and calls, including groups, use the Signal Protocol end to end."
    },
    "no_phone_number": {
      "title": "No phone number needed",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://support.signal.org/hc/en-us/articles/6712070553754-Phone-Number-Privacy-and-Usernames",
      "note": "A phone number is required to register a Signal account, but it is hidden by default and contacts can be reached by username."
    },
    "metadata_protection": {
      "title": "Metadata protection",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://signal.org/blog/sealed-sender/",
      "note": "Uses the Signal network, where sealed sender hides the sender from the server."
    },
    "decentralized": {
      "title": "Decentralized",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "Connects to the central Signal service."
    }
  },
  "tests": {
    "ssllabs": null,
    "observatory": null,
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [],
    "tested_at": "2026-10-01T06:38:22.511Z"
  },
  "last_modified": "2026-10-01T06:56:31Z"
}