Generated at build time · October 9, 2026

Proof, not promises.

This page is rebuilt from the repository every time the site is deployed. Each figure below is computed from the signed rule pack and our own guard scripts — and you can reproduce every one of them with a single command.

Verify it yourselfExplore all 106 rules

Summary

Findings at a glance

Six checks, each tied to the file it was computed from.

  1. T-01Pass

    0

    Ad & analytics SDKs

    Source scripts/no-trackers.mjs

  2. T-02Pass

    0

    Tracker hosts in shipped code

    Source scripts/no-trackers.mjs

  3. T-03Pass

    0

    Third-party requests on this site

    Source Content-Security-Policy

  4. T-04Pass

    None

    Data the apps send by default

    Source docs/PRIVACY.md

  5. T-05Pass

    106

    Rules in the signed pack

    Source shared/rules/default.rulepack.json

  6. T-06Pass

    182

    Protected paths

    Source shared/rules/default.rulepack.json

Signature

The rules are signed. The build checks the signature.

Cleanup rules are only loaded when their Ed25519 signature verifies. Before writing this page, the build re-verified the pack with the same canonical-JSON code the engines use.

Signed rule packVerified
Pack ID
cleanspeed.default
Version
1.1.0
Published
Algorithm
Ed25519 · CSCJ v1
SHA-256 of the pack file
709e24ff6ef12732e0c75105cbe9b84beccb09671832b00798bf4b9bb02320f1
Public-key fingerprint (SHA-256)
9ac0b5eaca12c043b384a43a7ad49e6b17eb94cf4ba2eb2e7cabff7880bc1f77
Signature (base64)
IOi2UPU8lIUf781IpDtcQbPdRPgQQMiljL91pOK5hvu4tK+enNAItaJkSJdocsWO0JsiUuDpfA9uJM7pR8UxBA==
Public key
shared/rules/keys/dev-public.ed25519.pem

The pack in the repository is signed with the development key. Release builds are re-signed with the production key in CI; its fingerprint will be listed here once the first release ships.

Verify it yourself

  1. Check the signature with the reference engine (Node.js 22.18 or later, nothing to install):

    git clone https://github.com/work517/cleaner.git && cd cleaner
    node packages/core/src/cli.ts verify-pack \
      --rulepack shared/rules/default.rulepack.json \
      --sig shared/rules/default.rulepack.sig \
      --pubkey shared/rules/keys/dev-public.ed25519.pem

    Expected: rule pack cleanspeed.default@1.1.0: signature OK, 106 rules

  2. Recompute the public-key fingerprint:

    openssl pkey -pubin -in shared/rules/keys/dev-public.ed25519.pem -outform DER | sha256sum

    Expected: 9ac0b5eaca12c043b384a43a7ad49e6b17eb94cf4ba2eb2e7cabff7880bc1f77

  3. Or download the exact files this page was generated from:

Tracker guard

Zero trackers — enforced by a script, not a promise

Every build scans dependency manifests and shipped source for 41 ad and analytics SDK identifiers and 14 tracker hosts. A single match stops the build.

$ node scripts/no-trackers.mjs
✓ no-trackers: 0 ad/analytics SDKs, 0 tracker hosts
Captured while this page was being generated.
SDK identifiers checked
41
Tracker hosts checked
14
Matches found
0

Third-party requests on this site0

The Content-Security-Policy only allows this site’s own origin. Scripts, styles, images and fonts are all self-hosted, and there is no analytics beacon.

default-src 'self';
script-src 'self' 'sha256-3mvNHCv+5a9eUj798Ymg77dAOQmoHWXVrawyHN29DCQ=';
style-src 'self';
img-src 'self' data: blob:;
font-src 'self';
connect-src 'self';
manifest-src 'self';
worker-src 'self';
frame-src 'none';
object-src 'none';
base-uri 'self';
form-action 'self';
frame-ancestors 'none';
upgrade-insecure-requests

Check the live header yourself:

curl -sI https://safecleanup.app/en/trust/ | grep -i content-security-policy

Data & releases

Your data, and our releases

What the apps send by default

Nothing.

Scans, file names, file contents, app lists and logs stay on your device. A report leaves it only if you choose to share it — and only after redaction.

Read the privacy policy

Checksums & SBOM

Each tagged release is assembled by CI and published with these files next to the downloads:

  • SHA256SUMSSHA-256 checksums of every release file
  • *.cdx.jsonCycloneDX software bill of materials
  • default.rulepack.sigRule pack signed with the production key

No public release yet. Checksums and SBOMs will appear on GitHub Releases with the first version — until then, we won’t show placeholder hashes.

Open GitHub Releases

Check downloaded files against the published list:

sha256sum --check --ignore-missing SHA256SUMS

Benchmarks

How we compare

Results from the benchmark harness in the repository, shown exactly as measured.

How we compare
TestCleanSpeedBaseline
scan.10k.filesPerSec13,034 files/s4,780 files/s
scan.10k.peakRss123 MB130 MB
duplicates.10k.durationMs772 ms1,098 ms
duplicates.10k.bytesReadPct29.24 %34.89 %
duplicates.10k.peakRss134 MB167 MB
redact.10k.buildReportMs6.6 ms19.3 ms
scan.100k.filesPerSec15,739 files/s4,598 files/s
scan.100k.peakRss194 MB223 MB
duplicates.100k.durationMs8,433 ms12,187 ms
duplicates.100k.bytesReadPct26.49 %39.85 %
duplicates.100k.peakRss228 MB299 MB
redact.100k.buildReportMs53.1 ms232.3 ms
quarantine.itemsPerSec334 items/s287 items/s
quarantine.restoreItemsPerSec570 items/s427 items/s
journal.appendsPerSec3,160 appends/s3,046 appends/s
scan.1m.filesPerSec15,301 files/s4,334 files/s
duplicates.1m.durationMs114,106 ms171,965 ms
duplicates.1m.bytesReadPct24.36 %62.35 %

Source: packages/core/bench/results.json · docs/BENCHMARKS.md · October 9, 2026

Disclosure

Found a security issue? Tell us first.

Report vulnerabilities privately by email or through a GitHub security advisory. We reply to every report.

security@safecleanup.appsecurity.txtPrivate advisory

Good-faith research that follows our policy is welcome — we will not take legal action. Read the security policy

  1. Acknowledgement within 3 business days
  2. Initial assessment within 10 business days
  3. Fix targets: critical 30 days, high 60 days, others 90 days

Transparency

Everything you can inspect

The files that decide what CleanSpeed may touch are public, versioned and reviewed like code.