09 — CleanMyMac parity analysis
Scope: [P0-09-follow-up]. Written 2026-08-09 against CleanMyMac 5.5.7 (released 2026-07-22)
and against the mac-cleaner tree at commit 9bc06e2.
Why this doc exists. The P0-10 plan review cut 12 features permanently and deferred 12 more,
mostly to remove the privileged helper and to protect the honesty positioning. The user has now
asked for CleanMyMac parity. This document does not re-argue those cuts. It prices parity:
what each gap costs, which gaps cannot be closed without reintroducing the privileged helper, and
which cannot be closed without an explicit exception to
docs/research/06-honesty-contract.md. Those two lists (§5, §6) are decisions the user must make
knowingly; everything else is scheduling.
Every CleanMyMac claim below is cited inline to MacPaw’s own pages. Nothing here was verified by
running CleanMyMac — the app was never launched, downloaded, or installed
(CLAUDE.md, “NEVER STEAL THE USER’S SCREEN”).
STEP 1 — What CleanMyMac actually ships in 2026
Version 5.5.7, 2026-07-22. Supported OS: macOS 11 Big Sur → macOS 26 Tahoe; Catalina and earlier are dropped. 320 MB install, 1200×800 minimum display. (whats-new, operating-systems)
The authoritative machine-readable taxonomy is MacPaw’s own Feature availability and differences article, which enumerates every Module → Category → Group with per-edition availability. There is no standalone “Cleanup” or “System Junk” article for CleanMyMac 5 — that article exists only for the legacy CleanMyMac X, and its category list is materially different (Photos Junk, Unused Disk Images, Old Updates and macOS Localizations existed in X and do not exist in 5).
1.1 Smart Care — the one-click front door
Five routines in one pass (smart-care):
| # | Routine | Scope inside Smart Care |
|---|---|---|
| 1 | Cleanup | System junk, mail attachments, trash bins — items auto-selected for removal |
| 2 | Protection | Quick Scan for malware — found threats auto-selected |
| 3 | Performance | Suggests periodic maintenance scripts + Flush DNS Cache |
| 4 | Applications | Recommends app updates (excludes system apps and macOS updates) |
| 5 | My Clutter | Duplicate files in the Downloads folder only |
Tunable per module/category/group in Settings → Scanning → Smart Care; deselected modules still appear, greyed out.
1.2 Cleanup — 12 System Junk groups + Mail Attachments + 3 Trash Bins
From missing-features. “AS” = present in the Mac App Store edition.
| Group | AS |
|---|---|
| Broken Login Items | ❌ |
| Broken Preferences | ✅ |
| Deleted Users | ❌ |
| Document Versions | ✅ |
| iOS Device Backups | ❌ |
| Language Files | ❌ |
| System Cache Files | ❌ |
| System Log Files | ❌ |
| Universal Binaries | ❌ |
| User Cache Files | ✅ |
| User Log Files | ✅ |
| Xcode Junk | ✅ |
Plus Mail Attachments (“remove locally stored email attachments … keeping your messages intact”, my-tools) and Trash Bins in three groups: Startup Drive Trash, External Drive Trash, Local Mail Trash.
Behavioural detail from the legacy-but-still-accurate group docs (cleanmymac-x/system-junk): Document Versions auto-selects only versions created <4 h apart and always keeps the latest; Xcode Junk never auto-selects Module Cache or Archives.
1.3 Performance — 8 maintenance tasks + 2 managers
maintenance-tasks. All eight are ❌ in the App Store edition.
- Flush DNS Cache
- Free Up Purgeable Space (added 5.0.5)
- Reindex Spotlight
- Repair Disk Permissions
- Periodic Scripts — macOS Ventura 13 and earlier only
- Speed Up Mail (reindex Mail’s database)
- Free Up RAM — Intel Macs only
- Thin Time Machine Snapshots — only when Time Machine is configured
Two of the eight are therefore already dead on our target platform: Periodic Scripts does not run on macOS 26, and Free Up RAM does not run on Apple Silicon. MacPaw ships them; they do not execute for a Tahoe/M-series buyer.
Plus Login Items and Background Items managers — ✅ in every edition, including App Store. There is no separate “Launch Agents” manager in v5 and no “Rebuild Launch Services” task.
1.4 Protection
- Malware Removal, Moonlock Engine, 18 declared malware classes (Adware, Backdoor, Botnet, Dropper, Exploit, Installer, Keylogger, Miner, PUA, Ransomware, Riskware, Rootkit, Spyware, Stealer, Trojan, Virus, Worm, Other) (malware-removal). MacPaw cites AV-TEST 99% detection / 0% false positives and +89% scan speed on M-series (moonlock-engine).
- 3 scan modes — Quick / Balanced / Deep (protection-scan-modes).
- 5 extra scan targets — DMGs, email attachments (requires FDA), archives, USB drives, iCloud files (protection-scan-options).
- Real-time Protection Monitor — runs with the app closed and the Menu off (protection-details).
- Background scanning — periodic deeper scans on MacPaw’s own schedule (background-scanning-on-off).
- Protection Sonar — green/yellow/red radar status widget in the Menu.
- PUA detection with published criteria (potentially-unwanted-applications).
- Privacy Items — exactly 5 groups (privacy): Safari (❌ AS), Google Chrome, Firefox, Recent Items Lists, Wi-Fi Networks (❌ AS). Per-browser items: Autofill Values, Browsing History, Cookies, Downloads History, HTML5 Local Storage (Safari), Saved Passwords (Firefox/Chrome), Search Queries (Chrome), Tabs from Last Session. Only Safari, Chrome and Firefox — no Edge, Brave, Arc or Opera. Wi-Fi Networks removal is impossible since macOS Sonoma — CleanMyMac lists the networks and then deep-links you to System Settings to delete them.
- Application Permissions (❌ AS) — review/revoke camera, microphone, screen recording, contacts, files/folders, photos (app-permissions).
- No chat/messaging privacy module and no anti-tracking feature exist in v5.
1.5 Applications
- Uninstaller (✅ all editions) — app + components outside
/Applications. Groups: All Applications, Unused (>6 months), Suspicious (developers/sources in Russia and Belarus), Selected, Stores, Vendors, Plugins (uninstaller). - Updater — 4 groups: App Store Updates (❌ AS), Custom Updates, macOS Updates (❌ AS), Sparkle Updates.
- Leftovers — 2 groups: Installers, Leftover Files — including leftovers of apps already removed (my-tools).
- Since 5.5.5 the module scans in the background so results are reviewable mid-scan.
- There is no “Extensions” module in v5 — that was CleanMyMac X. Its job is split across Leftovers and Performance → Login/Background Items.
1.6 My Clutter — 4 categories
Identical in all editions.
- Large & Old Files — this is the old standalone feature, now a category. Scans a chosen location, filters ≥ 50 MB, groups by kind/size/access date, auto-selects nothing, and deletes permanently, bypassing the Trash (large-and-old).
- Duplicates — auto-suggests files from the last three months, smart selection per group, deletes bypassing Trash (duplicate-files).
- Similar Images — near-identical/burst shots; Photos-app images go to Recently Deleted, everything else is deleted permanently (similar-images).
- Downloads — 3 sub-groups only: Google Chrome, Safari, Slack.
1.7 Space Lens
Reintroduced in 5.1.0 (2025-06-12) with the bubble redesign. Scans internal drives, external drives or a single folder; bubbles plus size-sorted list; storage breakdown chart with four segments — Used, Free, Purgeable, Selected; drill-down with breadcrumbs and history; system files macOS needs are non-selectable; Review-and-Remove panel (space-lens, space-lens-results).
1.8 Cloud Cleanup
New in 5.2.1 (iCloud/Google Drive/OneDrive); Dropbox added in 5.3.0. Four capabilities: delete cloud-only files without a browser, delete from Mac + cloud in one action, Unsync (free local space, keep the cloud original), and find large cloud files / redundant local copies (cloud-cleanup).
Per-provider: iCloud Drive is local-only, one account at a time (Apple policy forbids web access); Google Drive and OneDrive support web app and/or desktop app, multiple accounts; Dropbox is web-only (cloud-cleanup-icloud, cloud-cleanup-google-drive, cloud-cleanup-onedrive, cloud-cleanup-dropbox). Three of the four providers are network + OAuth features.
1.9 CleanMyMac Menu — 9 monitors, 11 alerts
| Monitor | Content |
|---|---|
| Mac Health | Aggregate score: Excellent → Good → Fair → Requires Attention → Critical (mac-health) |
| Protection (❌ AS) | Attack status, monitor state, malware-DB freshness, Sonar |
| Storage | Free space (yellow <10%), breakdown chart (Applications/Desktop/Documents/Downloads/Other), Trash size, Disk Health from SMART availableSpare, Disk Temperature (Normal ≤50 °C / Warning 51–70 / Critical ≥71) |
| Memory (RAM) | Available RAM + Free Up button (labelled Optimize in the App Store edition), Allocation chart (Active/Wired/Compressed), Pressure, Swap file size, Top Consumers with hover-to-Quit |
| Battery | Charge state, time to discharge, Health (actual÷designed mAh), cycles, Temperature |
| CPU | Usage, system-vs-user load chart, Temperature (Normal ≤55 / Warning 56–75 / Critical ≥76), Mac Uptime (restart suggested after ~7 days), Top Consumers with hover-to-Quit |
| Network | Interface, connection type, security rating by protocol (WEP→WPA3), connection time, VPN, live up/down speeds, speed test |
| Connected Devices | Cable/Bluetooth/Wi-Fi devices, <20% battery pinned red |
| Recommendations | Unused-feature nudges, uninstall-on-drag-to-Trash offer, weekly cleanup reminders, overfilled-Trash and cluttered-drive reminders, low-memory warnings, quit-hung-apps |
11 alerts: Battery Drain · Empty Trash · Heavy RAM Usage · Hung Apps · Low Bluetooth Device Battery (❌ AS) · Low External Drive Space · Low Free Space · Malware Detection (❌ AS) · Uninstall Apps Correctly · Update Apps (❌ AS) · Update Payment Details.
1.10 My Tools · My Activity · Smart Insights
- My Tools (5.5.0, 2026-04-02) — 17 pinnable tools with a Favorites section: App Leftovers, App Updater, Application Permissions, Background Items, Downloads, Duplicate Finder, Large and Old Files, Login Items, Mail Attachments, Maintenance Tasks, Malware Finder, Privacy Items, Similar Images, System Junk, Time Machine Snapshot, Trash Bins, Uninstaller.
- My Activity (5.4.0, 2026-02-26) — dashboard: Communications, Mac Health, Recommendations, Usage statistics; local + cloud cleanup progress, protection insights, “time saved”.
- Mac Health score — 8 named factors (detected malware, critical disk health, critical battery health, low disk space, pending app updates, unused apps, overfilled Trash, long uptime) plus whether FDA is granted, whether a scan ran recently, whether the Menu or real-time monitoring is off, and which modules you have not used.
- Smart Insights (5.2.6, 2025-10-20) — Apple Intelligence on-device tooltips explaining what a file is and whether it is safe to remove; appears in Cleanup, Protection, Performance and Applications. Requires Apple Silicon + macOS 26 + Apple Intelligence enabled (introducing-smart-insights).
1.11 Scheduling — there is none in the consumer product
This is the single most commonly mis-stated thing about CleanMyMac, and it matters for our roadmap. Nothing in MacPaw’s CleanMyMac 5 knowledge base documents a user-configurable schedule, and no feature deletes anything unattended. What runs on its own is: background malware scanning on MacPaw’s own (non-configurable) schedule which detects and notifies only; event-driven real-time malware monitoring which alerts only; the CleanMyMac self-updater every ~6 h; and weekly Menu reminders. MacPaw states plainly: “CleanMyMac only operates when you explicitly initiate it.” (full-disk-access, protection-details, cleanmymac-updater)
Genuine scheduled scans and cleanups exist only in CleanMyMac Business, as admin-dashboard automation tasks (cleanmymac-business/smart-scan).
1.12 Direct-edition-only features
The App Store edition loses 20+ groups (missing-features):
- Cleanup: Broken Login Items, Deleted Users, iOS Device Backups, Language Files, System Cache Files, System Log Files, Universal Binaries
- Protection: Safari privacy, Wi-Fi Networks privacy, Application Permissions
- Performance: all 8 maintenance tasks
- Applications: App Store Updates, macOS Updates
- Menu: Protection Monitor, Low Bluetooth Device Battery / Malware Detection / Update Apps alerts
My Clutter, Space Lens and Cloud Cleanup are identical across all three editions.
1.13 Privilege model
- Full Disk Access is needed by three components — CleanMyMac, CleanMyMac Health Monitor, CleanMyMac Menu — registered during the first Smart Care scan (full-disk-access).
- CleanMyMac Agent is a root helper installed on demand with the admin password, required for exactly four things (cleanmymac-agent): (1) removing system files — system caches, system logs, language files, Xcode files; (2) running maintenance scripts; (3) uninstalling App Store apps and apps involved in system processes; (4) removing detected malware.
- Three background items need “Allow in the Background” approval: Menu, Health Monitor, Updater (background-items).
So CleanMyMac runs one root daemon plus three background agents. Our v1.0 runs zero of either (spec §1 WHAT). That is the structural fork in the road for every helper-gated row below.
1.14 Price and licensing (USD, checked 2026-08-08/09)
| Plan | 1 Mac | 2 Macs | 5 Macs |
|---|---|---|---|
| Annual | $39.95/yr | $63.95/yr (list $79.90) | $127.95/yr (list $199.75) |
| Monthly | $9.95/mo | $15.95/mo | $32.95/mo |
| One-time | $119.95 | $191.95 | $383.95 |
- Subscriptions auto-renew. Coupon discounts are first-year only (“Discounts apply to the first year of subscription only”) — they renew at list (purchase-options).
- One-time purchase covers the current major version only; the next major version is a paid, discounted upgrade. Subscription includes major upgrades.
- Mac App Store: free download, IAP — $39.99/yr, $9.99/mo, Plus $65.99/yr; licence covers all Macs on the Apple Account; refunds are Apple’s, MacPaw cannot issue them.
- Setapp includes CleanMyMac: $14.99/mo, or $8.99/mo billed yearly (1 Mac) (setapp.com/pricing).
- Trial: 7 days, all features, from my.macpaw.com — but the MacPaw-Store trial requires payment details and auto-converts unless cancelled. The often-quoted “500 MB cleanup limit” is legacy CleanMyMac Classic/3 shareware, not v5.
- Refunds: 30 days for annual and one-time, 14 days for monthly, initial purchase only — renewals are not refundable (refund-policy).
- Standing discounts: 40% off year one for users of a competing cleaner (proof required), 30% loyalty, 30% education, 50% Apple/Claris employees (discounts).
- Install-base claims: “29 million downloads” (cleanmymac.com), “every 5th Mac on Earth has a MacPaw app” (macpaw.com/about).
Price relationship to us. Our $49 one-time / 2 Macs (docs/spec.md §7.1) is 1.23 years of
their 1-Mac annual, 41% of their 1-Mac lifetime, and 26% of their 2-Mac lifetime. Our
14-day trial requires no card; theirs is 7 days and does. Our refund window is 30 days on
everything, self-serve; theirs excludes renewals.
STEP 2 — What mac-cleaner actually ships today
Verified against code at 9bc06e2, not against the docs. Method: read every file in
Sources/Modules*/, Sources/CleanerUI/, Sources/CleanerKit/SmartScan.swift, and every rule ID
in /Users/avantgarde/code/dfacto.ai/mac-cleaner-rules/rules/*.yaml.
2.1 The manifest as it exists — 38 rules across 8 files
apps.yaml 6 apps.leftover-{application-support,caches,launch-agents,logs,preferences,saved-state}
dev-docker.yaml 2 dev-docker.{build-cache,dangling-image}
developer.yaml 16 developer.{xcode-derived-data,xcode-archives,xcode-device-support,
simulator-caches,simulator-devices-unavailable,simulator-runtimes,
npm-cache,pnpm-store,cargo-cache,go-cache,gradle-cache,maven-repository,
homebrew-cache,pip-cache,node-modules-stale,playwright-browsers}
discover.yaml 1 discover.large-folder
files.yaml 3 files.{downloads-installers,large-old,ios-device-backups}
junk.yaml 4 junk.{user-caches,user-logs,trash,volume-trash}
logs.yaml 1 logs.diagnostic-reports
system.yaml 5 system.{library-caches,library-logs,diagnostic-reports,rotated-logs,temp-folders}
The apps.* (6) and system.* (5) rules are written but unreachable: AppsModule.scan
(Sources/ModulesApps/AppsModule.swift:26) and SystemModule.scan
(Sources/ModulesSystem/SystemModule.swift:26) both return []. They are placeholder conformances
that prove the CleaningModule contract compiles. 27 of 38 rules are live.
2.2 Per-feature status
| Feature | Status | Evidence in code | Why / where decided |
|---|---|---|---|
| Trash, startup + all mounted volumes | SHIPPED | ModulesJunk/TrashModule.swift, junk.trash + junk.volume-trash |
04 rank 11 — 1.1 G |
| Downloads installer sweep (.dmg/.pkg/.iso) | SHIPPED | ModulesFiles/DownloadsModule.swift, files.downloads-installers |
04 rank 7 — 3.94 G |
| Byte-identical duplicate installers | SHIPPED | ModulesFiles/InstallerDuplicateDetector.swift (169 lines, content-hash) |
04 rank 7 — 3× UTM.dmg |
User caches ~/Library/Caches |
SHIPPED | ModulesJunk/CachesModule.swift, junk.user-caches, incl. require_owner_not_running probe |
04 rank 8 — 2.9 G |
| User logs + user diagnostic reports | SHIPPED | ModulesSystem/LogsModule.swift, junk.user-logs + logs.diagnostic-reports, require_no_open_fd |
04 rank 10 — 1.1 G |
| Xcode DerivedData / Archives / DeviceSupport | SHIPPED | ModulesJunk/DevXcodeModule.swift, 3 rules |
04 rank 3 |
| Simulator caches / stale devices / unused runtimes | SHIPPED | DevXcodeModule + SimulatorProbe.swift (201 lines, simctl) |
04 rank 3 — 23.7 G |
| Package-manager caches (npm, pnpm, cargo, go, gradle, maven, brew, pip, playwright) | SHIPPED | ModulesJunk/DevPkgModule.swift, 9 rules |
04 rank 4 — 11.6 G |
node_modules in stale projects |
SHIPPED | DevPkgModule, developer.node-modules-stale |
04 rank 6 — 10 G |
| Docker dangling images + build cache | SHIPPED | ModulesJunk/DevDockerModule.swift + DockerClient.swift (323 lines, Unix-socket Engine API) |
04 rank 5 — 5.6 G |
| Large & old files (≥ size, ≥ age) | SHIPPED | ModulesFiles/DiscoverModule.swift, files.large-old |
04 rank 9 — 12.8 G |
| Large unnamed folders (≥5 GB, no rule) | SHIPPED | DiscoverModule, discover.large-folder, .dangerous, typed confirmation |
04 rank 1 — the 72 G outlier |
| Smart Scan orchestrator + honest headline | SHIPPED | CleanerKit/SmartScan.swift (253 lines) — HeadlineAccounting has no initializer that accepts a total |
06 §4 |
| Inode + containment dedup | SHIPPED | ScanScheduler → ByteLedger.deduplicated |
spec §3.0 |
| 30-day quarantine, byte-exact restore | SHIPPED | CleanerKit/Quarantine/* (7 files) |
spec §4.1 |
| Single audited destructive API + confirmation token | SHIPPED | DestructiveOperations.swift, ConfirmationToken.swift; CI greps for delete primitives |
spec §4.3 |
Cloud-placeholder refusal (SF_DATALESS) |
SHIPPED | CleanerKit/CloudPlaceholder.swift |
08 R07 |
| Exclusion list (engine) | SHIPPED | Persistence/ExclusionList.swift, ExclusionEnforcingFileSystem.swift |
C-EXCL |
| Offline Ed25519 licensing + 14-day trial | SHIPPED | CleanerKit/Licensing/* (8 files) |
spec §7 |
| Published, signed, verifiable rules manifest | SHIPPED | Rules/ManifestSignature.swift, separate mac-cleaner-rules repo |
TR-1/TR-2 |
| App shell, Smart Scan UI, FDA onboarding | SHIPPED | CleanerUI/AppShellView.swift, SmartScanView.swift, OnboardingView.swift |
P3-U1/U2/U6 |
| Undo History screen | NOT BUILT (v1.0 scope) | AppShellView.swift:105 renders a CenteredStateView empty state only |
P3-U5 unstarted |
| Settings / exclusions / verify-rules screen | NOT BUILT (v1.0 scope) | no settings view in Sources/CleanerUI/ |
P3-U7 unstarted |
| Dedicated Review screen | PARTIAL | selection + clean flow lives inside SmartScanView results; no standalone screen |
P3-U3 unstarted |
| Scheduling | DEFERRED-v1.1, schema only | Persistence/SchedulesStore.swift — struct exists, no launchd surface, structurally cannot carry a ConfirmationToken |
spec §2.3; 06 row 36 |
| Privileged helper | DEFERRED-v1.1 | Sources/PrivilegedHelper/main.swift is 7 lines and prints a stub; not embedded, not linked |
plan-review CEO-2; spec §2.3 |
/Library/Caches |
DEFERRED-v1.1 | system.library-caches written, enabledByDefault: false, unreachable |
spec §2.3 (16 M readable floor) |
/Library/Logs |
DEFERRED-v1.1 | system.library-logs, same |
spec §2.3 (350 M) |
Root diagnostic reports / rotated logs / /private/var/folders |
DEFERRED-v1.1 | system.{diagnostic-reports,rotated-logs,temp-folders}, unreachable |
privilege-model §1 |
| App uninstaller + leftovers | DEFERRED-v1.1 | apps.leftover-* × 6 written, AppsModule.scan returns []; SmartScan.manualOnlyModuleIDs = ["apps"] |
spec §2.3; 08 R01/R03 |
| iOS device backups | DEFERRED-v1.1 | files.ios-device-backups written, enabledByDefault: false, no module claims it |
04 rank 16 — 0 B measured |
| Space Lens treemap | DEFERRED-v1.1 | data layer exists (BulkDirectoryReader, DirectoryRollup, CleanerBench/BenchTree); no view |
spec §2.3 |
| Whole-disk duplicate finder | DEFERRED-v1.1 | hash machinery exists in InstallerDuplicateDetector, scoped to Downloads |
spec §2.3; 08 R08 |
| Time Machine snapshot thinning | DEFERRED-v1.1 | no code | spec §2.3; 06 §2 |
| Mail attachment cache | DEFERRED-v1.1 | no rule, no code | 04 rank 15 — 9 M |
| Photos app cache (narrow) | DEFERRED-v1.1 | no code | 06 row 15 |
| Browser privacy — cache/cookie half | DEFERRED-v1.1 | no code | 06 row 27 REAL |
| Persistence audit / login & background items | DEFERRED-v1.1 | no code | 06 row 31; gated behind uninstaller |
| Performance diagnostics + menubar monitor | DEFERRED-v1.1 | no code | 06 rows 32/34 |
| iCloud local-copy eviction | DEFERRED-v1.1 | CloudPlaceholder refuses them today |
08 R07 Critical |
| Orphaned-file scanner | PERMANENTLY-CUT | — | spec §2.4; plan-review D1 upheld against challenge |
| Malware / adware scanner | PERMANENTLY-CUT | — | spec §2.4/§9; 06 row 30 FALSE; 08 hard rule 8; CEO-9 rejected |
| Repair permissions | PERMANENTLY-CUT | scripts/honesty-guard.sh greps repair permission |
03; 06 §2 “release blocker” |
| 9 of 11 maintenance scripts | PERMANENTLY-CUT | — | plan-review D3 — overturned harder than the spec’s own deferral |
| Free up RAM | PERMANENTLY-CUT | honesty-guard token free.{0,3}ram, no allowlist entry |
spec §2.4; 03 item 9 |
| Mac Health Score / any gauge | PERMANENTLY-CUT | honesty-guard tokens health score, mac score |
06 row 33 |
| Reclaim purgeable space | PERMANENTLY-CUT | honesty-guard token purgeable |
03 consequence 5 |
.lproj language stripping |
PERMANENTLY-CUT | — | 03 item 7; 08 R10 |
| Automatic / unattended deletion, “Smart Clean” | PERMANENTLY-CUT | honesty-guard tokens smart clean, auto[- ]clean |
05 §6.7; 06 row 36 |
| Similar-image finder | PERMANENTLY-CUT | — | spec §2.4; 08 R08 Critical |
| Photos “junk” as marketed | PERMANENTLY-CUT | — | 06 row 15 FALSE |
| App updater | PERMANENTLY-CUT | — | 06 row 29 COSMETIC, increases disk use |
| MDM / fleet, secure wipe | PERMANENTLY-CUT | — | 01 §2 |
| Universal binaries / app thinning | NOT-CONSIDERED | — | same class as .lproj: 08 R10 |
| Deleted Users, Document Versions | NOT-CONSIDERED | — | — |
| Broken login items, broken preferences | NOT-CONSIDERED / cut | — | module-map §1 row 6: “drop … broken prefs, login items”; 06 row 7 COSMETIC |
| Application Permissions (TCC) | NOT-CONSIDERED | — | — |
| Wi-Fi network privacy | NOT-CONSIDERED | — | — |
| Cloud Cleanup (Google/OneDrive/Dropbox) | NOT-CONSIDERED | — | — |
| My Tools / My Activity / Smart Insights | NOT-CONSIDERED | — | — |
| Hardware telemetry (SMART, temps, battery) | NOT-CONSIDERED | — | — |
Score. Of CleanMyMac’s ~70 individually named user-visible features, we ship 11 today, have 19 deferred with a written gate, 15 permanently cut with a ruling, and ~25 never considered. But those 11 cover ≈72.7 G of 04’s ≈73.1 G of measured reclaimable bytes on the audited machine. Feature count and byte coverage are almost inversely related in this category — that is the entire finding of §4.
STEP 3 — The gap table
Columns: Possible? = can it be built on macOS 26+ per docs/research/03-os-constraints.md.
Honesty? = would shipping it as CleanMyMac ships it require an exception to
docs/research/06-honesty-contract.md (✗ = yes, it would violate). Helper = requires the
privileged helper. Effort: S ≤ 1 lane-week · M 2–4 lane-weeks · L > 1 lane-month or
gated on the $12 k external XPC audit.
3.1 Cleanup
| # | CleanMyMac feature | Our status | The gap | Possible? | Honesty? | Helper | Effort | Impact | Bucket |
|---|---|---|---|---|---|---|---|---|---|
| 1 | User Cache Files | SHIPPED | None. We add a live-state probe and require_owner_not_running they do not document |
— | ✓ | — | — | — | NO GAP (ahead) |
| 2 | User Log Files | SHIPPED | None | — | ✓ | — | — | — | NO GAP |
| 3 | Xcode Junk | SHIPPED | None — we ship 6 rules incl. simulator runtimes/devices; theirs is one group | — | ✓ | — | — | — | NO GAP (well ahead) |
| 4 | Startup Drive Trash | SHIPPED | None | — | ✓ | — | — | — | NO GAP |
| 5 | External Drive Trash | SHIPPED | None (junk.volume-trash) |
— | ✓ | — | — | — | NO GAP |
| 6 | Local Mail Trash | NOT-CONSIDERED | No Mail container curation at all | YES (03: curated container subpaths, FDA) | ✓ | — | S | Low | BUILD LATER |
| 7 | Mail Attachments | DEFERRED-v1.1 | Whole feature | YES (03: hand-curated Mail Downloads subpath only) |
✓ (06 row 14 REAL) | — | S | Med | BUILD NOW |
| 8 | System Cache Files (/Library/Caches) |
DEFERRED-v1.1 (rule written) | Root-owned; unreachable without the helper | YES | ✓ (06 row 4 REAL) | YES | L | High | BUILD LATER (helper) |
| 9 | System Log Files (/Library/Logs) |
DEFERRED-v1.1 (rule written) | Same | YES | ✓ (06 row 5 REAL) | YES | L | High | BUILD LATER (helper) |
| 10 | iOS Device Backups | DEFERRED-v1.1 (rule written, off) | Rule exists, no module claims it | YES (FDA) | ✓ (06 row 16 REAL) | — | S | Med | BUILD NOW |
| 11 | Language Files | PERMANENTLY-CUT | Whole feature | Mechanically yes; 03 CAN-BUT-SHOULDN’T — invalidates the target app’s sealed-resource manifest, breaks Sparkle/MAS delta updaters | ✗ (06 row 18 NOT SHIPPED) | YES (root-owned bundles) | — | Low | REFUSE |
| 12 | Universal Binaries (app thinning) | NOT-CONSIDERED | Whole feature | Same failure mode as #11 — lipo-stripping a signed bundle breaks codesign --verify; 08 R10; Pearcleaner’s App Lipo is irreversible with no undo (02) |
✗ (same row as #11 by mechanism) | YES | — | Low | REFUSE |
| 13 | Broken Login Items | NOT-CONSIDERED / cut in module-map §1 | Whole feature | YES, user-level | ✓ but COSMETIC only (06 row 8) — zero bytes, no boot-time claim allowed | — | S | Low | BUILD DIFFERENTLY (see §4.3) |
| 14 | Broken Preferences | NOT-CONSIDERED / cut | Whole feature | YES | ✓ but COSMETIC (06 row 7) — may never claim it fixes crashes; honesty-guard greps fixes app crash |
— | S | Low | BUILD DIFFERENTLY |
| 15 | Deleted Users | NOT-CONSIDERED | Whole feature | YES with root | ✓ | YES | M | Low | BUILD LATER (helper) |
| 16 | Document Versions (/.DocumentRevisions-V100) |
NOT-CONSIDERED | Whole feature | Root-owned volume-root store; and the payload is the user’s own undo history — the macOS 14.4 iCloud-eviction bug that destroyed version history is 08 R07’s cited precedent | ✓ mechanically, but it is a data-loss class we have no fixture for | YES | M | Low | REFUSE (revisit only with a version-history-preservation fixture) |
3.2 Performance
| # | CleanMyMac feature | Our status | The gap | Possible? | Honesty? | Helper | Effort | Impact | Bucket |
|---|---|---|---|---|---|---|---|---|---|
| 17 | Flush DNS Cache | PERMANENTLY-CUT (D3) | Whole feature | YES | ✓ mechanically, but 06 §2 forces the string “no general speed effect” | YES | S | Low | REFUSE |
| 18 | Free Up Purgeable Space | PERMANENTLY-CUT | Whole feature | NO — 03 CANNOT. No third-party API forces CacheDelete; Finder’s own figure is documented as inaccurate | ✗ forbidden claim 3; honesty-guard token purgeable |
— | — | — | REFUSE |
| 19 | Reindex Spotlight | PERMANENTLY-CUT (D3) | Whole feature | YES (mdutil -E) |
✓ mechanically; 06 §2 forces “may take hours; fixes broken search results only” | YES | S | Low | REFUSE |
| 20 | Repair Disk Permissions | PERMANENTLY-CUT | Whole feature | NO — 03 CANNOT. Removed from macOS tooling in 2015 | ✗ forbidden claim 1; 06 §2 calls its presence anywhere in code or UI a release blocker | — | — | — | REFUSE |
| 21 | Periodic Scripts | PERMANENTLY-CUT (D3) | Whole feature | YES — but MacPaw ships it only on macOS ≤13. Our floor is macOS 26. There is no gap on our platform | ✓ mechanically; 06 §2: “macOS already runs these automatically” | YES | — | Zero | REFUSE (moot) |
| 22 | Speed Up Mail | PERMANENTLY-CUT (D3 class) | Whole feature | YES (reindex Mail’s SQLite envelope index) | ✓ mechanically, zero bytes, unmeasurable speed claim | — | S | Low | REFUSE |
| 23 | Free Up RAM | PERMANENTLY-CUT | Whole feature | NO as a claim — 03 CANNOT. And MacPaw ships it on Intel only, so it does not exist for an Apple-Silicon buyer either | ✗ forbidden claim 2; honesty-guard token free.{0,3}ram, deliberately with no allowlist entry |
— | — | — | REFUSE (moot on Apple Silicon) |
| 24 | Thin Time Machine Snapshots | DEFERRED-v1.1 | Whole feature | YES — 03 CAN, tmutil thinlocalsnapshots; but tmutil requires root on current macOS, and snapshot sizes are unreadable unprivileged |
✓ (06 §2 REAL) but reclaim is async: it may never join the same-second headline (06 §4 clause 4) | YES | M | High (the “my disk is full and I can’t find why” case) | BUILD LATER (helper) |
| 25 | Login Items manager | DEFERRED-v1.1 | Whole feature | YES for user agents (~/Library/LaunchAgents, launchctl bootout gui/$UID); NO for /Library/LaunchDaemons without root |
✓ as an inventory (06 row 8 COSMETIC) — no “faster boot” claim | Partial | M | Med | BUILD NOW (user-level half) |
| 26 | Background Items manager | DEFERRED-v1.1 | Whole feature | Same split | ✓ as inventory (06 row 31) — 08 R03 is the third-worst row in the register: CleanMyMac X breaking Cloudflare WARP is the cited precedent | Partial | M | Med | BUILD NOW (read-only + user-level toggle, hard vendor denylist) |
3.3 Protection
| # | CleanMyMac feature | Our status | The gap | Possible? | Honesty? | Helper | Effort | Impact | Bucket |
|---|---|---|---|---|---|---|---|---|---|
| 27 | Malware Removal (Moonlock, 18 classes) | PERMANENTLY-CUT | Whole feature | Mechanically yes with a signature feed; 07 budgets $0 for feeds as a scope decision | ✗ 06 row 30 FALSE; 08 hard rule 8; honesty-guard tokens virus, infected, malware(?! audit), threat detected |
YES (root persistence) | L | High (most-asked-for) | BUILD DIFFERENTLY (§4.3) |
| 28 | 3 scan modes (Quick/Balanced/Deep) | n/a | Falls with #27 | — | ✗ | — | — | — | REFUSE |
| 29 | 5 extra scan targets (DMG/email/archive/USB/iCloud) | n/a | Falls with #27 | — | ✗ | — | — | — | REFUSE |
| 30 | Real-time Protection Monitor | PERMANENTLY-CUT | Whole feature | YES (EndpointSecurity needs an Apple-granted entitlement) |
✗ #27’s ban plus spec §1 WHAT: “no background daemon” is a positioning claim we sell | YES | L | Med | REFUSE |
| 31 | Background malware scanning | PERMANENTLY-CUT | Whole feature | YES | ✗ same | YES | — | — | REFUSE |
| 32 | Protection Sonar (green/yellow/red) | PERMANENTLY-CUT | Whole feature | YES | ✗ 05 §6.5 bans red/yellow/green gauges not backed by an inspectable metric | — | — | — | REFUSE |
| 33 | PUA detection | PERMANENTLY-CUT | Whole feature | YES | ✗ 08 hard rule 8 — a threat judgement about a file | — | — | — | REFUSE |
| 34 | Privacy — Safari (cache/cookies) | DEFERRED-v1.1 | Whole feature | YES with FDA (~/Library/Containers/com.apple.Safari, curated subpaths per 03 item 11) |
✓ REAL (06 row 27) | — | S | High | BUILD NOW |
| 35 | Privacy — Chrome | DEFERRED-v1.1 | Whole feature | YES, plain ~/Library/Application Support/Google/Chrome |
✓ REAL | — | S | High | BUILD NOW |
| 36 | Privacy — Firefox | DEFERRED-v1.1 | Whole feature | YES | ✓ REAL | — | S | Med | BUILD NOW |
| 36b | Privacy — Edge/Brave/Arc/Opera | NOT-CONSIDERED | CleanMyMac does not ship these either — its browser list is exactly Safari/Chrome/Firefox. Shipping Arc + Brave is a lead, not a gap | YES | ✓ | — | S | Med | BUILD NOW (bundled with 34–36) |
| 37 | Privacy — history / autofill / saved passwords / recent items | DEFERRED / cut as a space claim | Whole feature | YES | ✓ only as a privacy action — 06 row 28 COSMETIC, contributes zero to the headline; deleting saved passwords is a data-loss class we would need a fixture for | — | S | Low | BUILD LATER |
| 38 | Privacy — Wi-Fi Networks | NOT-CONSIDERED | Whole feature | NO. Since macOS Sonoma even CleanMyMac cannot remove them — its own KB says it lists them and deep-links you to System Settings. And our user directive forbids handing the user a Settings chore as a fix | ✓ (listing is honest) but the action does not exist | — | — | Zero | REFUSE |
| 39 | Application Permissions (TCC) | NOT-CONSIDERED | Whole feature | Read: partially (TCC.db is SIP-protected; tccutil has no list verb). Revoke: only tccutil reset, per-service, and it re-prompts |
✓ as a read-only inventory | — | M | Med | BUILD LATER |
3.4 Applications
| # | CleanMyMac feature | Our status | The gap | Possible? | Honesty? | Helper | Effort | Impact | Bucket |
|---|---|---|---|---|---|---|---|---|---|
| 40 | Uninstaller (drag-app-here) | DEFERRED-v1.1 | Whole feature; AppsModule.scan returns [] |
YES for user-writable bundles; NO for .pkg-installed root-owned apps and App Store apps without root — spec §2.3: “a half-working uninstaller is worse than none” |
✓ (06 row 24 REAL, heuristic-scoped) | YES | L | Highest single parity gap | BUILD LATER (helper) |
| 41 | Leftover Files (of the app being removed) | DEFERRED-v1.1 (6 rules written) | Rules exist, module is a stub | YES with FDA | ✓ (06 row 24) — matching must stay exact-bundle-ID, never name-prefix (08 R01) | Partial | M | High | BUILD LATER (with #40) |
| 42 | Leftovers of apps already removed | PERMANENTLY-CUT | Whole feature | Mechanically yes | ✗ plan-review D1, challenged and upheld: the failure is silent and outlives the 30-day quarantine; the Review screen cannot mitigate a class the user cannot adjudicate. 08 R01 = H × Critical, the worst row in the register | — | — | Med | REFUSE (gate: a positive-evidence “provably gone” rule set + a measured byte case) |
| 43 | Installers group | SHIPPED | None — we also hash-dedup them, which they do not | — | ✓ | — | — | — | NO GAP (ahead) |
| 44 | Uninstaller groups: Unused (>6 mo) | NOT-CONSIDERED | Sort/filter affordance | YES | ✓ | — | S | Low | BUILD LATER (with #40) |
| 45 | Uninstaller group: Suspicious (Russian/Belarusian developers) | NOT-CONSIDERED | Whole feature | YES mechanically | ✗ A nationality-of-developer flag is a threat judgement with no technical basis (08 hard rule 8). 02 already records CleanMyMac flagging AdGuard as malware apparently over its founder’s nationality — cited in our own research as trust-destroying | — | — | — | REFUSE — and say why publicly |
| 46 | Updater — Sparkle | PERMANENTLY-CUT | Whole feature | YES | ✗ 06 row 29 COSMETIC and increases disk use; contributes zero to the headline in a disk-space product | — | M | Med | REFUSE |
| 47 | Updater — App Store | PERMANENTLY-CUT | Whole feature | Only by driving softwareupdate/MAS |
✗ same | — | — | Low | REFUSE |
| 48 | Updater — Custom | PERMANENTLY-CUT | Whole feature | YES | ✗ same | — | — | Low | REFUSE |
| 49 | Updater — macOS Updates | PERMANENTLY-CUT | Whole feature | softwareupdate --list |
✗ same; and MacPaw itself excludes it from Smart Care | — | — | Low | REFUSE |
3.5 My Clutter
| # | CleanMyMac feature | Our status | The gap | Possible? | Honesty? | Helper | Effort | Impact | Bucket |
|---|---|---|---|---|---|---|---|---|---|
| 50 | Large & Old Files (≥50 MB filter) | SHIPPED | None — and we also surface discover.large-folder, which has no CleanMyMac equivalent and was 04’s single largest finding (72 G) |
— | ✓ | — | — | — | NO GAP (ahead) |
| 51 | Duplicates (whole-disk) | DEFERRED-v1.1 / PARTIAL | We hash-dedup Downloads installers only | YES — InstallerDuplicateDetector already does content-hash identity + inode pre-dedup |
✓ (06 row 22 REAL) if resolution stays per-item and the loser is quarantined, never hardlinked over (08 R08) | — | M | High | BUILD NOW |
| 52 | Similar Images (perceptual) | PERMANENTLY-CUT | Whole feature | YES (Vision framework) | ✗ 08 R08 Critical — edited/higher-resolution versions get misidentified as the redundant copy; CleanMyMac deletes non-Photos matches permanently, bypassing the Trash | — | M | Med | BUILD DIFFERENTLY (§4.3) |
| 53 | Downloads (Chrome/Safari/Slack one-time files) | PARTIAL | We cover installers + duplicate installers; not general “one-time-use” downloads | YES | ✓ (06 row 2 REAL) | — | S | Med | BUILD NOW |
3.6 Space Lens, Cloud, Menu, cross-cutting
| # | CleanMyMac feature | Our status | The gap | Possible? | Honesty? | Helper | Effort | Impact | Bucket |
|---|---|---|---|---|---|---|---|---|---|
| 54 | Space Lens bubble map + drill-down | DEFERRED-v1.1 | No view. The data layer already exists — BulkDirectoryReader, DirectoryRollup, DirectoryWalker, CleanerBench/BenchTree |
YES | ✓ (06 row 21 REAL utility) — must carry no “GB reclaimable” copy; it is navigation, not a scan result | — | M | High | BUILD NOW |
| 55 | Storage breakdown chart incl. a Purgeable segment | NOT-CONSIDERED | Whole feature | Display: YES (03 CAN, “labeled as non-reclaimable”). Action: NO | ⚠️ Conflict inside our own docs. 03 consequence 5 permits displaying purgeable; 06 §3’s mechanical scan bans the token purgeable outright with no allowlist entry. Shipping the segment needs a one-line honesty-allowlist decision |
— | S | Low | BUILD LATER — decide the 03↔06 conflict first |
| 56 | Cloud Cleanup — iCloud Drive (unsync/evict) | DEFERRED-v1.1 | Whole feature. Today CloudPlaceholder refuses dataless files outright |
YES mechanically | ✓ (06 row 19 REAL, medium risk) | — | M | Med | BUILD LATER — gate is 08 R07 (post-Sonoma dataless deletes can propagate cloud-side; macOS 14.4 destroyed version history on eviction). Needs a zero-propagation fixture |
| 57 | Cloud Cleanup — Google Drive | NOT-CONSIDERED | Whole feature | YES, but it is OAuth + a network client + stored refresh tokens | ✗ against spec §1 WHAT, which sells “opens no socket” and “no network code path other than the user-initiated rules verification and the opt-out Sparkle check” | — | L | Med | REFUSE for 1.x |
| 58 | Cloud Cleanup — OneDrive | NOT-CONSIDERED | Same | Same | ✗ same | — | L | Low | REFUSE for 1.x |
| 59 | Cloud Cleanup — Dropbox (web-only) | NOT-CONSIDERED | Same | Same | ✗ same | — | L | Low | REFUSE for 1.x |
| 60 | Menu bar app (the container) | DEFERRED-v1.1 | Whole feature | YES | ⚠️ A menubar agent contradicts 02’s positioning (“no background daemon”) which we sell against CleanMyMac’s Health Monitor. Shipping it costs that sentence | — | M | Med | BUILD LATER — explicit positioning trade |
| 61 | Mac Health score (5 bands, 8 factors) | PERMANENTLY-CUT | Whole feature | YES | ✗ 06 row 33 FALSE; 05 §6.5; honesty-guard tokens health score, mac score |
— | — | Med | BUILD DIFFERENTLY (§4.3) |
| 62 | Storage monitor: free space, Trash size, SMART Disk Health, Disk Temperature | NOT-CONSIDERED | Whole feature | YES — SMART availableSpare and NVMe temperature are readable unprivileged via IOKit |
✓ REAL, individual, inspectable metrics are explicitly allowed (06 rows 32/34; 05 §6.5) | — | M | Med | BUILD NOW (as part of an honest diagnostics readout) |
| 63 | RAM monitor: allocation, pressure, swap, top consumers | NOT-CONSIDERED | Whole feature | YES | ✓ for the metrics (06 row 32) — ✗ for CleanMyMac’s Free Up button next to them | — | S | Med | BUILD NOW (metrics) / REFUSE (the button) |
| 64 | Battery monitor: health %, cycles, temperature | NOT-CONSIDERED | Whole feature | YES, IOKit AppleSmartBattery |
✓ REAL | — | S | Low | BUILD LATER |
| 65 | CPU monitor: load, temperature, uptime, top consumers | NOT-CONSIDERED | Whole feature | YES | ✓ REAL (06 rows 32/34) | — | S | Low | BUILD LATER |
| 66 | Network monitor: Wi-Fi security rating, live speeds, speed test | NOT-CONSIDERED | Whole feature | YES, but the speed test is a network call | ⚠️ speed test contradicts the no-network claim; the security rating is honest | — | M | Low | BUILD LATER (minus the speed test) |
| 67 | Connected Devices monitor | NOT-CONSIDERED | Whole feature | YES | ✓ | — | S | Low | BUILD LATER |
| 68 | Recommendations monitor + weekly cleanup reminders | PERMANENTLY-CUT by policy | Whole feature | YES | ✗ 05 §6.1/§6.6 — unprompted urgency and in-product nagging of a paying customer; 02’s MacKeeper never-do list items 5–6 | — | — | Low | REFUSE |
| 69 | 11 issue alerts (Empty Trash, Low Free Space, Hung Apps, …) | NOT-CONSIDERED | Whole feature | YES | Mixed: “Low Free Space” is factual and fine; “Update Payment Details” in-product is exactly the dark pattern we sell against | — | S | Low | BUILD LATER (factual subset only) |
| 70 | Smart Care (one-click, auto-selects items for removal) | PARTIAL — we ship Smart Scan | Ours scans and selects nothing; theirs pre-selects and cleans in one press | YES | ✗ as CleanMyMac implements it. spec §3.0 [r2]: “nothing is ever pre-checked, in any configuration”. 05 §2 mandates the Review screen. Honesty-guard greps smart clean, auto[- ]clean |
— | — | High | BUILD DIFFERENTLY (§4.3) |
| 71 | Smart Selection (auto-preselect “safe” items) | Deliberately opposite | We pre-check nothing | YES | ✗ 05 §6 banned pattern | — | — | Med | REFUSE |
| 72 | Safety Database (versioned, per-macOS, per-app) | SHIPPED and ahead | Ours is a separate public git repo, Ed25519-signed, with an in-app “verify against published rules” diff. Theirs is undisclosed | — | ✓ | — | — | — | NO GAP (well ahead) |
| 73 | Ignore List | PARTIAL | Engine done (ExclusionList, ExclusionEnforcingFileSystem); no UI |
YES | ✓ | — | S | Med | BUILD NOW (it is already v1.0 scope, C-EXCL/P3-U7) |
| 74 | My Tools (17 pinnable tools, favourites) | NOT-CONSIDERED | Whole feature | YES | ✓ | — | S | Low | BUILD LATER — a 17-tool launcher is only useful once there are 17 tools; we have 8 |
| 75 | My Activity dashboard | NOT-CONSIDERED | Whole feature | YES; ScanHistory + the audit log already store the data |
✓ except its Mac Health panel (#61) and “time saved” (unmeasurable) | — | M | Low | BUILD LATER |
| 76 | Smart Insights (Apple Intelligence “is this safe to remove?”) | NOT-CONSIDERED | Whole feature | YES — Apple Silicon + macOS 26 + Apple Intelligence, on-device Foundation Model | ⚠️ An LLM-generated safety opinion is a per-file judgement we cannot audit; our manifest reasoning string is the same affordance, deterministic, published and diffable |
— | M | Med | BUILD DIFFERENTLY (§4.3) |
| 77 | Scheduling / automation | DEFERRED-v1.1, schema only | Smaller than assumed: CleanMyMac’s consumer product has no user-facing scheduler at all. Only CleanMyMac Business does | YES (launchd) | ✓ scan-and-notify only; ✗ unattended deletion (06 row 36) | — | M | Low | BUILD LATER |
| 78 | CleanMyMac Business / MDM / admin dashboard | PERMANENTLY-CUT | Whole product line | YES | ✓ | — | L | Low | REFUSE for 1.x (01 §2: unaddressable as scoped) |
| 79 | Mac App Store edition | n/a | We cannot have one | NO — 03 CANNOT. Sandbox and FDA are mutually exclusive; Apple rejects the temporary-exception approximation | — | — | — | — | REFUSE (structural) — and note theirs loses 20+ groups |
Row count: 79 features assessed (76 numbered + 36b + 55 + 79). Of these, 13 are NO GAP or ahead.
STEP 4 — Ranked recommendation
Bucket counts (66 gaps, excluding the 13 no-gap rows):
| Bucket | Count |
|---|---|
| BUILD NOW | 12 |
| BUILD LATER | 21 |
| BUILD DIFFERENTLY | 6 |
| REFUSE | 27 |
4.1 BUILD NOW — 12, ranked by impact ÷ effort
| Rank | Gap | Rows | Effort | Impact | Why it is first |
|---|---|---|---|---|---|
| 1 | Browser privacy — cache + cookies for Safari, Chrome, Firefox, and (a lead over CleanMyMac) Brave, Edge, Arc | 34–36, 36b | S | High | Pure caches-shaped rule work: curated subpaths, existing RuleWalkScan, existing live-state probe. 06 row 27 is REAL, so the bytes count toward the headline. This is the single highest-recognition CleanMyMac category we can close in under a week, and shipping 6 browsers to their 3 is a strictly-better line on a comparison table. |
| 2 | Whole-disk duplicate finder | 51 | M | High | InstallerDuplicateDetector already implements content-hash identity and inode pre-dedup; the work is scope + a side-by-side review UI, not an algorithm. Gate: 08 R08’s fixture suite (hardlink pair never offered as a duplicate; the loser is quarantined, never hardlinked over). CleanMyMac deletes duplicates bypassing the Trash; our 30-day quarantine is the differentiator on their strongest My Clutter feature. |
| 3 | Space Lens equivalent | 54 | M | High | The data layer is already built and benchmarked (BulkDirectoryReader, DirectoryRollup, BenchTree). This is a view over data we already compute, and it directly serves 04’s #1 finding (the 72 G unnamed folder). Hard constraint: no “GB reclaimable” string anywhere in it (06 row 21). |
| 4 | Ignore-list / settings / verify-rules UI | 73 | S | Med | Already v1.0 scope (C-EXCL, C-VERIFY, P3-U7) and simply not built. Every parity claim below is worse without an exclusion affordance, and “verify against published rules” is the feature CleanMyMac structurally cannot copy. |
| 5 | Downloads: extend beyond installers to general one-time-use downloads | 53 | S | Med | One rule plus an age/extension predicate on a module that already exists and already has the highest-confidence finding in 04. |
| 6 | Mail attachment cache | 7 | S | Med | 06 row 14 REAL, 03 permits it as a hand-curated container subpath. Only 9 M on the audited machine, but it is a named CleanMyMac group and closing it costs one rule. |
| 7 | iOS device backups | 10 | S | Med | files.ios-device-backups is already written and merely disabled and unclaimed. Wiring it to a module is hours, not days. 0 B on the audit machine, multi-GB on a phone-syncing machine. |
| 8 | Login Items + Background Items inventory (user-level) | 25, 26 | M | Med | Both are ✅ in every CleanMyMac edition including App Store, so their absence is conspicuous. Ships as an inventory with provenance (parse the plist, show the owning vendor), never a “faster boot” claim. Non-negotiable: 08 R03’s hard vendor denylist — CleanMyMac X breaking Cloudflare WARP badly enough to force a factory reset is the cited precedent, and repeating it would be the worst possible parity own-goal. |
| 9 | Honest diagnostics readout: free space, Trash size, SMART disk health, disk/CPU temperature, memory pressure, swap, uptime, top CPU/RAM consumers | 62, 63 (metrics only) | M | Med | 06 rows 32/34 explicitly permit individual inspectable metrics; only the aggregate score is banned. This closes 4 of the Menu’s 9 monitors’ content without the Menu, the daemon, or the score. |
| 10 | Local Mail Trash | 6 | S | Low | Falls out of #6’s Mail-container curation for free. |
| 11 | Broken preferences / broken login items — as an inventory, not a fix | 13, 14 | S | Low | Cheap, and it removes two conspicuous names from the “they have it, you don’t” list. Must ship COSMETIC: zero headline bytes, and the string “this does not fix app crashes.” |
| 12 | Privacy: history / autofill / recent items | 37 | S | Low | Bundle with #1. Zero headline bytes (06 row 28), privacy value only. Do not ship saved-password deletion without a dedicated fixture. |
Total BUILD NOW effort: ~6 S + ~4 M ≈ 14–18 lane-weeks, fully parallelisable across the JUNK, FILES, SYSTEM and UI lanes on the module-map §4 wave plan. None of it needs the helper. None of it needs an honesty exception.
4.2 BUILD LATER — 21
Helper-gated cluster (ships together, after the external XPC audit — spec §2.3, §12):
system caches (#8), system logs (#9), root diagnostic reports / rotated logs / /private/var/folders,
Deleted Users (#15), Time Machine snapshot thinning (#24), app uninstaller (#40), its leftovers
(#41), uninstaller groups (#44), the system half of Login/Background Items (#25/#26).
Effort: L, gated on $12,000 and a passing audit. Impact: this cluster is the entire
remaining “why can’t it clean system junk / uninstall apps” objection. spec §2.3 already
predicts it: “‘it can’t clean system caches’ is the most common thing a reviewer will notice.”
Not helper-gated: Application Permissions read-only inventory (#39, M/Med), iCloud unsync (#56, M/Med — gated on an R07 zero-propagation fixture), the purgeable segment of a storage breakdown (#55, S — decide the 03↔06 conflict first), menu-bar app (#60, M — costs the “no background daemon” sentence), battery monitor (#64), CPU monitor (#65), network monitor minus the speed test (#66), connected devices (#67), factual alerts subset (#69), My Tools (#74), My Activity (#75), scheduling scan-and-notify (#77).
4.3 BUILD DIFFERENTLY — 6
The user need is real; CleanMyMac’s implementation is dishonest, unsafe, or both.
| CleanMyMac feature | What they ship | What the honest version is |
|---|---|---|
| Smart Care (#70) | One press: scans, auto-selects junk and malware, cleans | Smart Scan — already built. Runs all modules in one pass, produces one ranked list and one exact number that is the arithmetic sum of rows already on screen. HeadlineAccounting has no initializer that can accept a total, so a projection cannot be assigned even by mistake. Nothing is pre-checked. Marketing line: “One press to see everything. Two to delete anything.” |
| Mac Health score (#61) | One 5-band score from 8 undisclosed-weight factors, plus “have you used our modules lately” folded into your Mac’s health | A flat, inspectable metric list: free space, disk health from SMART availableSpare, disk temperature, battery health, memory pressure, uptime, pending items. Each shows the raw number and where it came from. No roll-up, no colour band that isn’t backed by a documented Apple threshold. Marketing line: “We show you seven numbers. We don’t average them into one we made up.” |
| Malware Removal (#27) | Signature scanning, 18 threat classes, real-time daemon, red badge counters | A persistence audit (06 row 31): enumerate every LaunchAgent, LaunchDaemon, login item and background item; show its label, its path, its signing authority and its owning vendor parsed from the plist — and flag nothing. Copy: “{n} background items found — review; nothing here is flagged as malware.” The honest sell is the absence: “We don’t guess whether a file is malware. We show you exactly what runs at boot and who signed it, and let you decide.” 02 already records CleanMyMac’s detection as its weakest feature (Macworld left AdWind partly installed, missed a fake Flash installer, flagged AdGuard). |
| Similar Images (#52) | Perceptual grouping; non-Photos matches deleted permanently, bypassing the Trash | Exact-duplicate images only, by content hash, resolved per item, loser quarantined for 30 days. If perceptual grouping is ever added it ships as a review surface with zero pre-selection and copy that says “none of these are exact duplicates” (06 row 23), never as a cleanup action. |
| “Free Up RAM” / “Optimize” (#63’s button) | A button that forces memory recompression and calls it optimisation | Memory pressure, allocation and swap displayed, with no button. One line of copy: “macOS manages memory automatically; unused RAM is wasted RAM. Nothing here is a problem to fix.” Note that CleanMyMac itself only ships this on Intel — on Apple Silicon their own button does not exist. |
| Smart Insights (#76) | On-device LLM tooltips telling you whether a file is safe to remove | The rule’s published reasoning string, already required by spec §6 TR-1 and already shown in the inspector. It is deterministic, it is in a public git repo, it is Ed25519-signed, and the user can diff the copy running on their Mac against the published one. Marketing line: “Not an AI’s opinion — the actual rule, published, signed, and diffable.” |
4.4 REFUSE — 27
Cannot be done honestly or safely on macOS 26. Grouped by the answer we give a user who asks “why doesn’t it have X?”
“macOS removed it / never allowed it” (5) — Repair Disk Permissions (#20, no-op since El Capitan 2015), Free Up Purgeable Space (#18, no third-party API can force CacheDelete; Finder’s own figure is documented as inaccurate), Free Up RAM (#23, and CleanMyMac ships it on Intel only), Wi-Fi network privacy (#38, impossible since Sonoma — CleanMyMac lists them and sends you to System Settings), a Mac App Store edition (#79, Sandbox and FDA are mutually exclusive and Apple rejects the workaround).
“It’s a placebo and we said we’d ship none” (4) — Flush DNS Cache (#17), Reindex Spotlight (#19), Speed Up Mail (#22), Periodic Scripts (#21 — moot: CleanMyMac only runs it on macOS ≤13, and our floor is macOS 26). Answer: “macOS already does these. Every honest description of them ends in ‘no general speed effect.’ We’d rather not have the button.”
“It breaks the app it’s cleaning” (2) — Language Files (#11), Universal Binaries (#12). Both strip files from a signed bundle, invalidating its sealed-resource manifest and its Sparkle/MAS delta updater. 08 R10; KeePassXC #4496 is the cited real-world breakage.
“We won’t make threat judgements” (6) — Malware Removal as marketed (#27→§4.3), scan modes (#28), extra scan targets (#29), real-time Protection Monitor (#30), background scanning (#31), PUA detection (#33). Plus Suspicious apps by developer nationality (#45) — refuse this one loudly; 02 records CleanMyMac flagging AdGuard apparently over its founder’s nationality, and it is the clearest available illustration of why we don’t ship verdicts.
“A gauge that isn’t backed by an inspectable metric is a lie” (3) — Mac Health score (#61→§4.3), Protection Sonar (#32), Smart Selection auto-preselect (#71).
“An updater makes your disk fuller, not emptier” (4) — Sparkle (#46), App Store (#47), Custom (#48), macOS (#49) updates. Answer: “This is a disk-space app. Updates use more disk, not less, and Homebrew, Sparkle and the App Store already do this for you.”
“We can’t tell, and being wrong is silent” (2) — Leftovers of apps already removed (#42; D1 upheld — 08 R01 is H × Critical, Pearcleaner shipped this bug twice), Document Versions (#16; root-owned, and the payload is the user’s undo history).
“It contradicts what we sell” (4) — Google Drive (#57), OneDrive (#58) and Dropbox (#59) cloud cleanup all need OAuth, a network client and stored refresh tokens, against spec §1 WHAT’s “opens no socket”; Recommendations / weekly nag notifications (#68) are 05 §6.1/§6.6 and MacKeeper never-do items 5–6.
Plus CleanMyMac Business / MDM (#78) — refused for 1.x on 01 §2’s “unaddressable as scoped.”
STEP 5 — Gaps that CANNOT be closed without the privileged helper
Decide this once; it is a cluster, not nine decisions. spec §2.3: “the privileged-helper cluster ships together, or not at all.”
| # | Feature | Why root |
|---|---|---|
| 8 | System Cache Files /Library/Caches |
Root-owned; 04 could only read a 16 M floor unprivileged |
| 9 | System Log Files /Library/Logs |
Root-owned; 350 M measured |
| — | system.diagnostic-reports, system.rotated-logs, system.temp-folders |
Root-owned; rules written, enabledByDefault: false |
| 15 | Deleted Users | Another user’s home directory |
| 16 | Document Versions | /.DocumentRevisions-V100 at volume root (also refused on data-loss grounds) |
| 24 | Thin Time Machine Snapshots | tmutil thinlocalsnapshots / deletelocalsnapshots require root; snapshot sizes are unreadable unprivileged |
| 40 | App uninstaller | .pkg-installed and App Store apps are root-owned in /Applications. A no-root uninstaller can only remove user-writable bundles — “a half-working uninstaller is worse than none” (spec §2.3) |
| 41 | Leftovers in /Library/* |
Root-owned support/agent files |
| 25/26 | The system half of Login/Background Items | /Library/LaunchDaemons needs root to modify (the user half does not) |
| 11/12 | Language Files, Universal Binaries in root-owned bundles | Root-owned (also refused on code-signature grounds) |
| 30/31 | Real-time malware monitoring | Root daemon + an Apple-granted EndpointSecurity entitlement (also refused) |
What reintroducing the helper costs, from the register and the budget, not from opinion:
- R04 returns — the only Critical row in the risk register caused by our own code, and the
exact bug Pearcleaner shipped in production (GHSA-gr2j-65fh-8pvc: unauthenticated
runCommandexecuting arbitrary shell as root becauseshouldAcceptNewConnectionreturnedtrueunconditionally). Same class hit Forklift, GOG Galaxy, Acustica and Sparkle (CVE-2025-10016/10015). - $12,000 for the full-scope external XPC audit (07 §3), repeating on any major version that touches the helper/XPC boundary.
- The
SMAppServiceinstall/repair/unregister lifecycle, the root-restore path in §4.2, P10 in §5, HR7’s static + runtime tests, and a second manual System Settings trip for the user (Login Items & Extensions) — 03 confirms Apple removed the auto-prompt path. - The loss of one marketing sentence we currently sell: “it also runs nothing as root and opens
no socket,” which spec §1 calls a claim “both free competitors cannot match without becoming a
different product.” It is also mechanically checkable today (
PrivilegedHelperis 7 lines, not embedded, not linked).
What it buys: ≈366 MB of 04’s ≈73 GB — 0.5% of measured bytes — plus the uninstaller, which measured 0 bytes but is the feature users most expect. So the case for the helper is entirely a perceived-parity case, not a byte case. That is a legitimate reason to take it; it just should be taken with that sentence in front of you, because CEO-2 rejected it on exactly the byte arithmetic and nothing in this research changes the arithmetic.
STEP 6 — Gaps that CANNOT be closed without an honesty-contract exception
Each row names the specific clause and, where one exists, the CI token in
scripts/honesty-guard.sh that will fail the build. A “yes” here means a release-blocking guard
must be disabled or allowlisted, not merely that a doc needs editing.
| # | Feature | Clause it breaks | CI token |
|---|---|---|---|
| 20 | Repair Disk Permissions | 06 §2: “appearing anywhere in code or UI is a release blocker”; forbidden claim 1 | repair permission |
| 23 | Free Up RAM | 06 forbidden claim 2; spec §2.4 made it permanent everywhere with no carve-out, on the explicit ground that “when the honesty gate must be disabled to let a feature through, the feature is the problem” | free.{0,3}ram — the token was deliberately left with no allowlist entry |
| 18 | Free Up Purgeable Space | 06 forbidden claim 3; 03 consequence 5 | purgeable |
| 55 | Purgeable segment in a storage breakdown chart | ⚠️ Genuine internal conflict: 03 consequence 5 permits display-only disclosure; 06 §3’s mechanical scan bans the token outright. Displaying it honestly needs one allowlist line and a doc reconciliation | purgeable |
| 61 | Mac Health score | 06 row 33 FALSE; 05 §6.5 | health score, mac score |
| 32 | Protection Sonar (red/yellow/green) | 05 §6.5 — gauge not backed by an inspectable metric | — |
| 27 | Malware Removal as marketed | 06 row 30 FALSE; 08 hard refusal rule 8; 05 §6.5 | virus, infected, malware(?! audit), threat detected |
| 30/31/33 | Real-time monitor, background scanning, PUA | Same as #27, plus spec §1’s “no background daemon” | same |
| 45 | “Suspicious apps” by developer nationality | 08 hard rule 8; 02’s AdGuard precedent | — |
| 70 | Smart Care’s auto-select-and-clean | 05 §2 Review-screen mandate; spec §3.0 [r2] “nothing is ever pre-checked, in any configuration”; 06 row 36 | smart clean, auto[- ]clean |
| 71 | Smart Selection pre-checking | 05 §6 banned patterns | — |
| 68 | Recommendations / weekly nag | 05 §6.1 (manufactured urgency), §6.6 (nagging a paying customer) | — |
| 46–49 | App / macOS updater | 06 row 29 COSMETIC — contributes zero to the headline and increases disk use | — |
| 11/12 | Language Files, Universal Binaries | 06 row 18 NOT SHIPPED; 08 R10 (safety, not just claim) | — |
| 42 | Leftovers of already-removed apps | plan-review D1 upheld under challenge; 08 R01 = H × Critical | — |
| 52 | Similar Images as a cleanup action | 08 R08 Critical; spec §2.4 | — |
| 57–59 | Google/OneDrive/Dropbox cloud cleanup | spec §1 WHAT’s “opens no socket” (positioning, not the honesty contract proper) | — |
| 60 | Menu-bar background agent | 02 positioning: “no background daemon” is the sentence we sell against CleanMyMac’s Health Monitor | — |
| 76 | Smart Insights (LLM safety opinions) | Not a named ban, but an unauditable per-file judgement is against TR-1’s “no reasoning outside the published manifest” | — |
The honesty tax, stated plainly. 21 of CleanMyMac’s ~70 features cannot be copied as they are implemented. Seven of those 21 are already dead or dying on our own platform — Periodic Scripts (macOS ≤13 only), Free Up RAM (Intel only), Wi-Fi privacy (impossible since Sonoma), Repair Disk Permissions (no-op since 2015), Free Up Purgeable Space (no API exists), and the App Store edition’s 20-group deficit. CleanMyMac ships buttons for several things that do not execute on an Apple-Silicon Tahoe Mac. Full honest parity on our platform is not 70 features — it is about 49, and we already ship or have a written path to 45 of them.
Bottom line
- Closing every gap that is honest, safe and needs no root costs ~14–18 lane-weeks (§4.1) and takes us from 11 shipped features to 23.
- The next tier is one decision, not nine: the privileged-helper cluster — system caches, system logs, the uninstaller, TM snapshot thinning and the system half of the login-items manager — costs $12,000 + R04 + the “never runs as root” sentence, and buys 0.5% of measured bytes plus the feature users most expect. Take it as a perceived-parity decision or not at all.
- 27 CleanMyMac features should never be built, and for 7 of them the reason is that they no longer work on modern macOS — including in CleanMyMac itself.