CoreTend

Know what your Mac is holding. Take the space back.

CoreTend reads supported locations on-device and explains each finding. Sensitive actions require a reviewed selection and explicit confirmation before eligible items are handed to the macOS Trash.

Local scans No account No telemetry Apache-2.0

0.9.1-rc.5 · macOS 14.0+ · arm64
Free and open source · Not Developer ID signed · Not notarized · see the checksums

CoreTend — Macintosh HD Example data Confirmation required
Storage Reading local metadata…
Nothing has been removed.

02 Workflow

Three moves. Nothing leaves until the third.

Most cleaners delete first and tell you after. CoreTend reverses the order: read, show, then act — and only when you ask.

Every step stays reversible until the Trash is emptied.

  1. 01

    Scan

    Storage, Space Lens and Duplicates stream results while they scan; Applications and Integrity also inspect local metadata. Scan indexes stay on the Mac. Only a manual update check requests the public latest.json manifest.

    Cooperative pause, resume and cancellation are available in Storage, Space Lens and Duplicates.
  2. 02

    Review

    Each row carries its path, size and reason. Quick Look and Finder help you verify it. Some low-risk Storage categories and non-kept duplicate copies start selected, so review them before acting.

    System locations are protected. Space Lens can scan the home folder or a folder you choose; Duplicates also includes Documents among its supported locations.
  3. 03

    Act

    Every result remains inspectable before action. After explicit confirmation, CoreTend asks macOS to place eligible items in the Trash and adds an aggregate entry to the local record, which can be exported as CSV or JSON.

    CoreTend has no built-in restore action after removal. Check the Trash and use Put Back when macOS successfully placed the item there.

03 What ships

Eight modules. Nothing promised beyond them.

This is the actual architecture of 0.9.1. If a capability is not on this list, it is not in the app.

  • Home

    Dashboard

    App signature, Trash status, exclusions, free space, recent activity and shortcuts into the six primary workflows.

  • Scan

    Storage

    Caches, logs, crash reports, leftover installers, build data and forgotten downloads.

  • Map

    Space Lens

    A treemap you can walk into, with breadcrumbs, search and Reveal in Finder.

  • Match

    Duplicates

    Exact SHA-256 matching, keeper selection, Quick Look, Finder and CSV export.

  • Apps

    Applications

    Inventory of /Applications and ~/Applications, bundle-ID-associated data and detected update source.

  • Signals

    Integrity

    Download provenance, inspection of one selected app and launch-agent inventory. It is not an antivirus.

  • Record

    Activity

    Up to 500 aggregate local activities, with filters, safety log and CSV or JSON exports.

  • Control

    Settings

    Language, menu bar, exclusions, diagnostics, onboarding and manual update checking.

04 Findings

What a scan surfaces, and why.

A size on its own is not a decision. Every row carries the reason it was flagged, so saying no is as informed as saying yes.

Sample data. Your scan will look like no one else's.

~/Library · 4 groups Selection reviewed
Found 0 GB Nothing moved yet

05 Health

A read on the machine, not a cockpit.

CoreTend locally shows processor and memory use, free disk space and macOS's qualitative thermal state. The values below are interface examples, not measurements of your Mac.

CPU 0% 8 cores · light load
Memory 0.4 / 16 GB
Memory pressure normal
Disk 0%
112 GB free of 512 GB
Thermal state Nominal
Qualitative signal reported by macOS

06 Privacy

Built to be inspected, not believed.

A page promising privacy proves nothing. These are the inspectable boundaries: the code is public, scan data stays in one local database, and a manual update check contacts only the public release manifest.

  • Local store~/Library/Application Support/CoreTend/store.sqlite
  • NetworkNo telemetry, ads, account or device identifier. Manual update check via /latest.json.
  • RemovalsExplicit selection, confirmation, macOS Trash and aggregate local activity.
  • LicenceApache-2.0 · github.com/ahmetbsbnr/coretend
CoreTend — verified boundaries

07 Install

The public build is honest about Gatekeeper.

The public app is ad-hoc signed for bundle integrity, but it is not Developer ID signed or notarized. Gatekeeper therefore blocks the first launch. Verify the SHA-256 first, then use macOS's public override flow if you choose to continue.

  1. 1

    Open the .dmg, drag to Applications

  2. 2

    First launch is blocked: that is normal

  3. 3

    System Settings → Privacy & Security → Open Anyway, then confirm Open

SHA-256 b654975770cc1bfeb7e6a4f3cf180653a3182a55f8dc135db2083a72528998eb

08 FAQ

Answers before the download.

Does it send file names anywhere?

No. Scans stay on the Mac and this site has no analytics. There is no account, advertising, telemetry or device identifier. A manual update check requests only /latest.json and sends no file index.

Is it an antivirus?

No. The Integrity module reports macOS signals — provenance, quarantine, code signature, launch items. It does not detect malware and does not claim to.

Can I undo a removal?

CoreTend has no built-in restore action after removal. When macOS successfully placed an item in the Trash, use Finder → Trash → Put Back before emptying it.

Why the warning on first launch?

The public build is ad-hoc signed for bundle integrity, without Developer ID signing or notarization. After the first attempt, macOS offers a manual exception in System Settings → Privacy & Security. Verify the SHA-256 before continuing.

What if I remove something I needed?

System locations are protected and each result remains inspectable before confirmation. Duplicates also searches Documents, and some categories start selected, so always review the selection and check the Trash after acting.

Is there a price, a subscription, an account?

No to all three. CoreTend ships under Apache-2.0, with no pro tier and no locked features. The repository contains everything you run.

See what yours is holding.

A scan moves nothing. That is the point.

0.9.1-rc.5 · macOS 14.0+ · arm64 · Apache-2.0