Cleanup receipt

Verify a cleanup receipt

Paste a receipt link or code from the SafeCleanup app. Everything is checked here in your browser — the receipt is never sent to our server.

The receipt travels in the part of the link after “#”, which browsers never send to a server. This page doesn’t upload or store it.

To check a chain, paste several codes, one per line.

How it works

What this page checks

The same checks as the apps and the open-source reference engine, run locally with your browser’s built-in cryptography.

  • Valid, canonical receipt code

    The code is unpacked with size limits (no zip bombs) and must be the one canonical encoding of the receipt — no extra spaces, reordered keys or duplicates.

  • SHA-256 hash recomputed

    The SHA-256 hash is recomputed over the receipt’s canonical form. Any edited number, rule or timestamp changes it.

  • Totals add up

    Rule totals must add up to the overall totals and the risk breakdown, and the free-space change must match the before and after values.

  • Hash chain links (sequence and previous hash)

    Each receipt carries a sequence number and the hash of the previous one, so a removed or rewritten receipt breaks the chain.

  • Ed25519 device signature

    If the device signed the receipt, the Ed25519 signature is checked. A device key without a signature, or a chain where only some receipts are signed, is rejected.

  • Rule pack in the public transparency log

    The rule-pack version is matched against the public transparency log, so a receipt can’t claim rules that were never published.

Privacy

What a receipt never contains

  • No file or folder names, paths, user names or app lists — every text field is limited to IDs, versions, times and hashes.
  • Per-file details are reduced to one keyed fingerprint (a Merkle root) that only your device can open.
  • Verification runs in this page. The receipt isn’t uploaded, logged or stored.

More on how receipts and rules are verified: Trust proof · Privacy