Safety & recovery

Designed so you never lose a photo

Chronoframe copies, verifies, and records — it doesn't gamble. These are the guarantees the app is built on, from the first preview to the last receipt.

The guarantees

Eight promises, no fine print

  • Read-only sourceChronoframe only ever reads your source folder. It never moves, renames, edits, or deletes an original. Cleaning up the source is a manual choice you make later, yourself.
  • Preview before any changeOrganize shows the full transfer plan and Deduplicate shows every group before a file is touched. Nothing is copied or trashed until you approve it.
  • No overwritesIf a file with the same name already exists at the destination, Chronoframe keeps both. It never replaces one of your files with another.
  • Verified copiesEach file is written to a temporary location and only put into place once it's re-verified against the original, so a copy is never silently corrupt or truncated.
  • Trash, not deleteDuplicates you approve move to the macOS Trash, where you can recover them. Chronoframe has no hard-delete path at all.
  • One operation at a timeThe app, command-line tool, and system actions share a single destination lock, so two runs can never change the same library at once.
  • Receipts for every runTransfers, dedupe commits, and reorganize runs each write a receipt. Undo works only while files still match that receipt, so it never touches anything added or changed afterward.
  • Fail-closed on ambiguityWhen Chronoframe can't verify the state of a file or drive, it stops and asks rather than guessing. It never treats an inaccessible path as a missing one.

If something is interrupted

Interruptions leave evidence, not damage

Power loss, an unplugged drive, a force-quit — Chronoframe is built to pick up exactly where it stopped, and to be honest when it can't.

  • It records as it goes. Before mutating the destination, Chronoframe writes down what it's about to do, so an interruption always leaves a trail.
  • It reconciles on relaunch. Reopen the app with the destination drive connected and it checks durable copies, Trash, and move evidence before starting any new work.
  • It tells you what it needs. History surfaces states like Needs Drive, Trash Location Unverified, or Manual Recovery Needed when it can't safely finish on its own.
  • Your originals stay untouched. Through every recovery path, the source folder is never in play — the worst case is unfinished work at the destination, not lost photos.

Deduplicate, specifically

Removing a duplicate is the most careful thing the app does

Matched by content

Exact duplicates are found by comparing file bytes, not names. Similar-photo and visual-video matches are review-only and never auto-accepted.

Re-verified before Trash

Every planned removal is re-checked by content just before it moves. If a file, pair, or sidecar changed since the scan, it's preserved instead of deleted from a stale plan.

Recoverable as a unit

Approved files move to the macOS Trash together, with recovery metadata kept on-device, so a group can be rolled back cleanly.

Safety you can watch happen.

Run a preview on your own library. Nothing changes until you decide it should.

One-time purchase, no subscription, ever.