The product promise
Rules the implementation must be able to prove.
These are limits on the product, not broad guarantees about macOS or third-party tools.
Explain before moving
Every catalog item names its source, consequence and regeneration behavior. If the rule cannot meet the current safety checks, the app refuses it.
Show the exact list
A manual move uses a short-lived review record bound to the exact paths, rules, file types and measured sizes. A changed or reused record is refused.
Recovery has a real boundary
Ordinary catalog items move to a same-volume Vault for seven days. Guardian items stay for 30 days. Restore can fail if the original path has been replaced, the volume is unavailable, or the Vault is damaged; the app reports that instead of overwriting data.
Personal content is not selected for you
Large-file and age views are inspection-only. Age or size is not permission to remove a file.
No memory theatre
Memory is shown as pressure, holders and measured growth. The app does not claim that forcibly emptying memory improves the Mac.
Local storage analysis
File names, paths and local scan summaries stay on the Mac. Licence activation uses the signed key entered by the customer.
Reviewed removal rules
Automated removal is restricted to reviewed safe catalog rules. Owner-app, age, volume, Vault and size-ceiling checks can stop an action.
Say what could not be measured
Unreadable paths, unknown sizes, partial restores, uncertain Guardian outcomes and shared-block estimation limits remain visible.
What the Vault does not promise
The Vault is not a backup. Its retention ends, a drive can fail, and a user can empty it. Whole-volume APFS snapshots are separate and may be removed by macOS; they are never presented as per-file undo.