DDCC

You should not have to trust a program that deletes your files.

DDCC is built to be checkable. Every path is attributed by something on your Mac that declares the relationship. Every removal is tiered by what it costs you to be wrong. Destructive actions are Trash-first, opt-in, and confirmed. The source is there to read.

Download for macOS Free · Apple silicon & Intel · macOS 15+
3tiers
  • Tier 1 selected by default
  • Tier 2 unlocked per scan
  • Tier 3 needs the word typed

Tiers measure blast radius, not size.

Size is only one part of the decision. The tier comes from the recovery cost if removing the item turns out to be a mistake. When an item could sit in two tiers, it goes in the more cautious one.

TierWhat it meansHow it behaves
1 · SafeRegenerated automatically, at no cost but timeSelected by default
2 · CostlyComes back, but costs a download or a long rebuildLocked; unlocked per scan, priced first
3 · DestructiveHolds state that does not come backLocked; the only tier that requires typing DELETE
FIG. 01 The confirmation grouped by tier, with Trash as the default
A confirmation sheet reading Delete 3 items, this will free 4.48 GB, listing each path under a Safe heading, with an unchecked Permanently delete option.
Every path, listedThe actual items, grouped by how much it costs you to be wrong about them.
Permanent is uncheckedThe Trash is the default and the reversible option is the easy one.

Attribution is evidence, not resemblance.

Folder names can resemble app names without belonging to them. DDCC attributes a path when something declares the relationship, and the row says which declaration.

EvidenceWho declares itConfidence
Sandbox containermacOS, by bundle identifierDeclared
Application groupThe app's signed entitlementsDeclared
Homebrew zap stanzaThe cask authorDeclared
Installer receiptThe installer that wrote the filesDeclared
Broken dependency pointerA manifest naming a file that is goneProvable
A similarly named folderNobodyNot used

What DDCC's safety guard leaves alone.

REFUSED

Apple-owned paths

Apple's namespace is declined by name before any other rule runs.

REFUSED

Shallow, high-value folders

Your home directory and its document folders are protected by depth rules that no filter setting can override.

REFUSED

Paths outside allowed roots

Paths an app genuinely owns but which sit outside the folders DDCC may remove from are listed and left alone.

REFUSED

Root-owned files, without you

Removing an app installed for everyone goes through Finder, so macOS asks you for Touch ID. DDCC uses that system prompt instead of holding privileges itself.

FIG. 02 The privileged step performed by macOS
macOS asking for Touch ID or a password because Finder wants to move Microsoft Word to the Trash.
Finder performs the moveYour authentication authorizes Finder, and DDCC keeps no elevated rights.

No account. No telemetry. No network connection of any kind. The only program DDCC launches is Finder, and only to complete a removal you chose.

Download for macOS Free · Apple silicon & Intel · macOS 15+