What Freshist Never Deletes

Updated

Protected locations

Never moved — the folder and everything inside

  • /System
  • /usr
  • /bin
  • /sbin
  • /etc
  • /var
  • /private
  • /dev
  • /cores
  • /Library/Apple

Never moved — the folder itself

  • /
  • /Applications
  • /Users
  • /Library
  • /Volumes
  • ~
  • ~/Library
  • ~/Desktop
  • ~/Documents
  • ~/Downloads

~ is your home folder. Items inside these folders can be cleaned; the folders themselves stay.

Plus: any path belonging to endpoint security and MDM agents, wherever it is.

From the app's own protection rules — the same list it checks before every move.

Two kinds of protection

Freshist's file rules distinguish between two kinds of protected location:

  • Protected trees. Nothing inside these folders, at any depth, can be moved. This covers the parts of macOS that the system itself owns.
  • Protected folders. The folder itself can never be moved, but items inside it can — for example, ~/Library stays put while a single cache inside ~/Library/Caches can go to the Trash.

Before deciding, Freshist resolves symlinks and .. in the path, and compares names case-insensitively (as the Mac's file system does), so a path can't sneak past a rule by being spelled differently.

Security and management tools are off-limits

Many work Macs run endpoint security and MDM agents. Removing their files can trip tamper detection or break device management, so any path that belongs to one of these tools is refused — wherever it is on disk. System-cache cleaning skips their caches with a second, independent check.

Files owned by macOS

Some leftovers and system caches are owned by macOS (root) and can't be moved to your Trash. Freshist never pre-selects them. When you choose to remove them, a separate signed helper does the deletion, and it accepts only:

  • items one level inside /Library/Caches or /Library/Logs, for system caches, and
  • items one level inside a short list of system folders whose name matches the uninstalled app's bundle ID, for app leftovers.

Everything else is rejected by the helper itself, even if the request came from the app.

Everything else goes to the Trash

Whatever you clean or uninstall from your own user folder moves to the Trash, so you can restore it until you empty the Trash. Every destructive action is also written to a local log on your Mac at ~/Library/Logs/Freshist/.

Built to be trusted with your files.

  • Show before you remove

    Every file is listed with its exact size before anything happens. No blind “one-click clean”.

  • Refuse when unsure

    Risky or ambiguous items are never pre-selected. They're flagged “review” for you to decide.

  • Trash, not delete

    Everything goes to the Trash so you can undo. Permanent deletion is separate and explicitly confirmed.

  • Every action logged

    A plain, local log of every destructive action lives on your Mac, readable any time.

  • Zero telemetry

    No analytics, no accounts, no tracking network calls. It's a design constraint, not a promise.

  • Calm by default

    No nagging, no upsell screens, no manufactured urgency. One quiet app that respects your time.

Frequently asked questions

Can Freshist delete my documents?

Freshist won't move your Desktop, Documents or Downloads folders themselves, and it never removes anything you haven't seen in a list first. Clean only looks at caches, logs and similar rebuildable data; the folders it scans are listed in the cache guide.

What if I select something by mistake?

Items you clean or uninstall from your user folder go to the Trash, so you can put them back. Only root-owned system items are deleted permanently — those are never pre-selected.

Is Freshist safe on a work Mac?

Freshist refuses to move files whose path belongs to endpoint security or MDM agents, and its helper never deletes their caches, so it won't interfere with the security tools your IT team installed. Check your company's policy before installing any utility.