Disk analysers like QDirStat and Filelight tell you a directory is 8 GB. They
do not tell you that it is ~/.cache/go-build, that Go rebuilds it on the next
compile, and that deleting it costs you forty seconds. Chystik does.
It classifies what it finds into fifteen categories, states both what recovery
costs and whether Chystik may clean the exact item automatically, and — where
native-trash safety is verified — moves what you choose to the desktop trash,
never straight to unlink.
- Understands, not just measures. ~200 rules recognise package caches, build outputs, downloaded toolchains, AI model weights, agent transcripts, container layers and desktop junk — each with a sentence explaining what it is and how it comes back.
- Explains recovery. Automatic regenerates on its own. Rebuild / redownload costs time. Manual / irreplaceable cannot return on its own and is never bulk-selectable.
- Shows its cleanup authority. Catalog-backed findings state the exact rule, recovery class and upstream source. Auto-cleanable may join an automatic cleanup; review required, tool-managed and advisory only remain deliberate user decisions.
- Refuses to do damage. Every path passes through a guard before deletion:
system directories,
.git,.ssh,.gnupgand your settings are rejected outright, symlinks and Windows reparse points are never followed, and the scan root itself is never deletable. - Fail-closed cleanup. Linux, macOS and Windows deletion go through their native desktop recovery mechanisms. On a platform without a verified native-trash adapter, cleanup is disabled rather than falling back to direct deletion.
- Pruned parallel scan. Chystik classifies and prunes subtrees during its
parallel
jwalkwalk. See the reproducible benchmark methodology and reference measurements; timing depends on the machine, filesystem, target and cache state. - English and Ukrainian, detected from your locale.
See platform support for the current Linux/macOS/Windows capabilities and release status.
The category rail on the left answers "what is worth doing?"; the detail pane answers "what recovery costs, and may Chystik clean this?".
Every row carries the sentence explaining what it is and how it comes back —
Go build cache — rebuilt automatically by 'go build'. Findings that need a
command you run yourself (old snap revisions, unused Flatpak runtimes) show
that command instead of a checkbox, because Chystik will not run it for you.
The interface follows your locale; the same view in Ukrainian is at docs/img/screenshot-gui-uk.png.
Requires a Rust toolchain (1.80 or newer) and the usual desktop development libraries.
git clone https://github.com/pasichDev/chystik
cd chystik
cargo build --releaseThe binaries land at target/release/chystik-gui and target/release/chystik.
To register the desktop entry and icons for your user:
./packaging/install.shOn Debian/Ubuntu:
sudo apt install build-essential pkg-config libgtk-3-devOn Fedora:
sudo dnf install gcc pkgconf-pkg-config gtk3-develOn Arch Linux:
sudo pacman -S --needed base-devel cargo pkgconf gtk3 libxkbcommon-x11Tagged releases publish x86_64 artifacts on GitHub Releases. Choose the format
for your distribution; all three contain the GUI, chystik CLI, generated
manual/completions where the format supports them, and the same trash-only
cleanup contract.
Generic Linux desktops with a GTK-compatible X11 or Wayland session can use the AppImage:
chmod +x Chystik-<version>-x86_64.AppImage
./Chystik-<version>-x86_64.AppImageDebian and Ubuntu derivatives can install the Debian package:
sudo apt install ./chystik_<version>_amd64.debFedora and RHEL-compatible distributions can install the RPM package:
sudo dnf install ./chystik-<version>-1.x86_64.rpmArch users can build the versioned source recipe in packaging/arch:
cd packaging/arch
makepkg -siThe AppImage is a portable x86_64 release target, not a claim that every distribution, desktop environment, glibc version, or graphics stack is certified. See the support matrix for the tested environments and limitations.
Tagged releases also publish portable ZIP archives. Extract one archive and
run Chystik-GUI.exe for the desktop app or chystik.exe for the terminal;
no installer, administrator rights, or direct-delete mode is involved.
Expand-Archive .\Chystik-<version>-windows-x86_64.zip -DestinationPath .\Chystik
.\Chystik\Chystik-GUI.exe
.\Chystik\chystik.exe scan --safewindows-x86_64 is the release target for 64-bit Windows 10 and Windows 11.
windows-aarch64 is the native ARM64 archive for Windows 11 on Arm. Archives
are checksummed in SHA256SUMS; they are not code-signed yet, so Windows may
show a SmartScreen warning. See the support matrix for the distinction between
native CI evidence and a Windows 10 desktop acceptance run.
- Pick what to scan. Chystik offers your real mounted volumes; add any folder with Targets → Add folder.
- Press Scan. Results stream in as they are found.
- Work through the categories in the left rail, largest first.
- Select auto-cleanable ticks only exact findings eligible for automatic cleanup in the current category. Review-required items require a deliberate row selection; manual / valuable data is never bulk-selected.
- Move to Trash shows a full manifest — every path, its recovery class and cleanup policy, and a tick showing whether the safety guard will accept it. Read it.
Keyboard: / focuses the filter, Esc closes a dialog, Enter confirms one.
chystik-gui # normal launch
chystik scan --safe # read-only terminal scan
chystik clean . --safe --dry-run # inspect an auto-cleanable cleanup manifest
CHYSTIK_AUTOSCAN=1 … # start GUI scan immediately (headless smoke testing)
LANG=uk_UA.UTF-8 … # force GUI language
See CLI reference for JSON/JSONL contracts, confirmation
policy, exit codes, completions, and chystik(1).
This is a tool that deletes things, so the safety model is the product.
| Layer | What it does |
|---|---|
| Rules | Only match paths a rule explicitly recognises. There is no "delete anything over N GB". |
| Recovery | Every match carries the cost of losing it. Manual / irreplaceable data is excluded from bulk selection. |
| Cleanup policy & evidence | Catalog rules record whether Chystik may clean the exact path, its recovery class, and a vendor/upstream source. clean --safe remains compatible and means auto-cleanable: only DirectSafe automatic findings are eligible. |
| Size floor | Findings under 1 MiB are dropped, so the signal is not buried in noise. |
| Guard | chystik_core::guard::check runs before every deletion and refuses platform-protected roots, protected names, symlinks and anything outside the scan root. |
| Manifest | Nothing is deleted until you have seen the full list with per-item guard verdicts. |
| Capability | chystik_core::platform enables native-trash cleanup only where its safety contract is verified; every other target is scan-only. |
A crate-level test asserts that no rule can ever propose a path the guard refuses — the two cannot silently disagree.
It is still your disk. Rules can be wrong about your machine. Read the manifest.
Build artifacts · Package caches · IDE & toolchains · AI models · Browser & system · Android dev · AI agents · Containers · Installers · Games · Media · Messengers · Cloud sync · Office · System junk
crates/chystik-core scanner, rules, recovery, safety guard, reporting
src/platform/ target-selected host policy and capability seam
src/rules/ one module per domain; declarative catalog TOML + validator
src/guard.rs the last line of defence before any deletion
src/app.rs shared roots, filters, manifests and cleanup plans
src/config.rs versioned consent and never-touch policy
crates/chystik-cli scriptable frontend, JSON/JSONL, completions and man
crates/chystik-gui the desktop application (egui/eframe)
src/panels.rs window regions
src/modals.rs dialogs, including the first-run risk acknowledgement
locales/*.json translations — no Rust changes needed to add a language
packaging/ desktop entry, icon renderer, installer
site/ the GitHub Pages site, published from main by pages.yml
docs/img/ screenshots shared by this file and the site
See CONTRIBUTING.md. Adding a cleanup rule is usually a small declarative TOML entry plus evidence; that is the most useful contribution.
Security issues: see SECURITY.md.
MIT — see LICENSE.
Bundles IBM Plex Sans and IBM Plex Mono, © 2017 IBM Corp., under the SIL Open Font License 1.1. See NOTICE.
