What the apps send by default
Nothing.
Scans, file names, file contents, app lists and logs stay on your device. A report leaves it only if you choose to share it — and only after redaction.
Generated at build time · October 9, 2026
This page is rebuilt from the repository every time the site is deployed. Each figure below is computed from the signed rule pack and our own guard scripts — and you can reproduce every one of them with a single command.
Summary
Six checks, each tied to the file it was computed from.
0
Source scripts/
0
Source scripts/
0
Source Content-
None
Source docs/
106
Source shared/
182
Source shared/
Signature
Cleanup rules are only loaded when their Ed25519 signature verifies. Before writing this page, the build re-verified the pack with the same canonical-JSON code the engines use.
cleanspeed.default1.1.0Ed25519 · CSCJ v1709e24ff6ef12732e0c75105cbe9b84beccb09671832b00798bf4b9bb02320f1 9ac0b5eaca12c043b384a43a7ad49e6b17eb94cf4ba2eb2e7cabff7880bc1f77 IOi2UPU8lIUf781IpDtcQbPdRPgQQMiljL91pOK5hvu4tK+enNAItaJkSJdocsWO0JsiUuDpfA9uJM7pR8UxBA== shared/rules/keys/dev-public.ed25519.pemThe pack in the repository is signed with the development key. Release builds are re-signed with the production key in CI; its fingerprint will be listed here once the first release ships.
Check the signature with the reference engine (Node.js 22.18 or later, nothing to install):
git clone https://github.com/work517/cleaner.git && cd cleaner
node packages/core/src/cli.ts verify-pack \
--rulepack shared/rules/default.rulepack.json \
--sig shared/rules/default.rulepack.sig \
--pubkey shared/rules/keys/dev-public.ed25519.pemExpected: rule pack cleanspeed.default@1.1.0: signature OK, 106 rules
Recompute the public-key fingerprint:
openssl pkey -pubin -in shared/rules/keys/dev-public.ed25519.pem -outform DER | sha256sumExpected: 9ac0b5ea
Or download the exact files this page was generated from:
Tracker guard
Every build scans dependency manifests and shipped source for 41 ad and analytics SDK identifiers and 14 tracker hosts. A single match stops the build.
$ node scripts/no-trackers.mjs
✓ no-trackers: 0 ad/analytics SDKs, 0 tracker hostsThe Content-Security-Policy only allows this site’s own origin. Scripts, styles, images and fonts are all self-hosted, and there is no analytics beacon.
default-src 'self';
script-src 'self' 'sha256-3mvNHCv+5a9eUj798Ymg77dAOQmoHWXVrawyHN29DCQ=';
style-src 'self';
img-src 'self' data: blob:;
font-src 'self';
connect-src 'self';
manifest-src 'self';
worker-src 'self';
frame-src 'none';
object-src 'none';
base-uri 'self';
form-action 'self';
frame-ancestors 'none';
upgrade-insecure-requests
Check the live header yourself:
curl -sI https://safecleanup.app/en/trust/ | grep -i content-security-policy
Data & releases
Nothing.
Scans, file names, file contents, app lists and logs stay on your device. A report leaves it only if you choose to share it — and only after redaction.
Each tagged release is assembled by CI and published with these files next to the downloads:
SHA256SUMSSHA-256 checksums of every release file*.cdx.jsonCycloneDX software bill of materialsdefault.rulepack.sigRule pack signed with the production keyNo public release yet. Checksums and SBOMs will appear on GitHub Releases with the first version — until then, we won’t show placeholder hashes.
Check downloaded files against the published list:
sha256sum --check --ignore-missing SHA256SUMSBenchmarks
Results from the benchmark harness in the repository, shown exactly as measured.
| Test | CleanSpeed | Baseline |
|---|---|---|
| scan.10k.filesPerSec | 13,034 files/s | 4,780 files/s |
| scan.10k.peakRss | 123 MB | 130 MB |
| duplicates.10k.durationMs | 772 ms | 1,098 ms |
| duplicates.10k.bytesReadPct | 29.24 % | 34.89 % |
| duplicates.10k.peakRss | 134 MB | 167 MB |
| redact.10k.buildReportMs | 6.6 ms | 19.3 ms |
| scan.100k.filesPerSec | 15,739 files/s | 4,598 files/s |
| scan.100k.peakRss | 194 MB | 223 MB |
| duplicates.100k.durationMs | 8,433 ms | 12,187 ms |
| duplicates.100k.bytesReadPct | 26.49 % | 39.85 % |
| duplicates.100k.peakRss | 228 MB | 299 MB |
| redact.100k.buildReportMs | 53.1 ms | 232.3 ms |
| quarantine.itemsPerSec | 334 items/s | 287 items/s |
| quarantine.restoreItemsPerSec | 570 items/s | 427 items/s |
| journal.appendsPerSec | 3,160 appends/s | 3,046 appends/s |
| scan.1m.filesPerSec | 15,301 files/s | 4,334 files/s |
| duplicates.1m.durationMs | 114,106 ms | 171,965 ms |
| duplicates.1m.bytesReadPct | 24.36 % | 62.35 % |
Source: packages/core/bench/results.json · docs/BENCHMARKS.md · October 9, 2026
Disclosure
Report vulnerabilities privately by email or through a GitHub security advisory. We reply to every report.
security@safecleanup.appsecurity.txtPrivate advisory
Good-faith research that follows our policy is welcome — we will not take legal action. Read the security policy
Transparency
The files that decide what CleanSpeed may touch are public, versioned and reviewed like code.
Every cleanup rule with its paths, risk level and evidence link.
shared/rules/default.rulepack.jsonSigned rule pack: View sourceThe JSON Schema every rule must pass before it can be signed.
shared/schemas/rulepack.schema.jsonRule-pack schema: View sourceShared test cases so the Windows, Android and reference engines decide exactly the same way.
shared/rules/conformance/Conformance vectors: View sourcePath guard, signature check, quarantine and rollback — with tests.
packages/core/src/Reference engine: View sourceThe script behind the zero-trackers result above.
scripts/no-trackers.mjsTracker guard: View sourceThe generator of this very page. No tracking code, nothing hidden.
apps/web/This website: View sourceThreat model, signing, supply chain and disclosure policy.
docs/SECURITY.mdSecurity design: View sourceWhat is stored, where, and for how long.
docs/PRIVACY.mdPrivacy policy: View source