What Is ~/Library/Group Containers on Mac?

Your user folderUpdated

Definition
Full path
  • ~/Library/Group Containers
Scope
Your user folderInside your home folder — one copy per user account.
Freshist & this folder
Freshist checks this folder when uninstalling an app. When you uninstall an app, Freshist looks here for items that belong to it. Matches on the app's bundle ID can be pre-selected; name-only guesses are labeled “not sure” and never pre-selected. Removed items go to the Trash, so you can undo.

From Freshist's own cleaning rules — the same catalog the app uses.

Sandboxed apps normally can't see each other's files. When a developer needs two pieces of software to share data, such as a main app and its Today widget, a Safari extension or a helper, they declare an app group in the app's entitlements. macOS then creates one shared folder for the group in ~/Library/Group Containers, and every member can reach it through FileManager's containerURL(forSecurityApplicationGroupIdentifier:).

Folder names follow the group identifier:

Name patternExample formWho uses it
Team ID prefixABCDE12345.com.example.suiteThird-party apps from one developer
group. prefixgroup.com.apple.notesApple apps and newer third-party groups

A sample Mac had 158 group containers using 3.6 GB, and a single chat app's folder accounted for 1 GB of that.

Why it's real data, not cache

Because widgets, extensions and the main app all read the same files, developers tend to put their primary database here. Apple Notes keeps its local store in group.com.apple.notes. Office suites and messaging apps commonly keep accounts, message history or shared settings here. Delete the wrong group container and the app starts as if new, with only what it can download again.

Why leftovers stay

A group container belongs to no single app, so removing one app from /Applications never removes it. Even when every app in the group is gone, the folder stays until someone deletes it. Reinstalling the app later reconnects it to the old data.

Inspecting it read-only

ls ~/Library/Group\ Containers
du -sh ~/Library/Group\ Containers/* 2>/dev/null | sort -h | tail -10

Some folders may refuse access from Terminal unless it has Full Disk Access. That's expected and harmless.

To find which developer a Team ID belongs to, look at an installed app from that developer:

codesign -dv /Applications/AppName.app 2>&1 | grep TeamIdentifier

Removing a leftover group container

  1. Identify the developer through the Team ID or the reverse-DNS part of the name.
  2. Confirm that none of that developer's apps that use the group are still installed, including menu bar helpers and extensions.
  3. Make sure anything you care about is synced or exported.
  4. In Finder, choose Go → Go to Folder…, enter ~/Library/Group Containers, and move the folder to the Trash.

What not to delete

Leave every group.com.apple.* folder alone: they belong to Notes, Messages-related services, widgets and other parts of macOS you still use. Don't delete a group container to fix a misbehaving app without a backup. The per-app counterpart is ~/Library/Containers, and script folders for app groups also appear in Application Scripts. See how to uninstall apps completely for the full checklist.

Sources

Frequently asked questions

What do the codes at the start of folder names mean?

A prefix such as ABCDE12345 is the developer's Team ID, assigned by Apple. Folders beginning with group. use the newer naming style; Apple's own app groups look like group.com.apple.notes.

Can I delete a group container if I removed only one app from the group?

No. The other apps in the group still read and write the same folder. Wait until every app from that developer that uses the group is uninstalled.

Why does an app ask to 'access data from other apps' when it opens a group container?

macOS Sonoma started protecting app containers, and macOS Sequoia extended that protection to group containers. Apps outside the group need your permission to read them.

Keep reading