Security
How RefundRadar protects your data · last reviewed August 2026
Your Temu login stays on your phone, and the price checks and claims run entirely on your device, talking directly to Temu — we never see your password or your Temu session, and Temu itself rejects duplicate claims. Finding a drop and claiming it never requires your data to leave your phone. We do keep a copy of your order and refund data on our servers — to show your savings history across your devices and to run and improve the service — and we back it all with free, automated security scans against the OWASP MASVS mobile-security standard.
At a glance
Your Temu login
- Your password is never collected. You sign in on Temu's own login page inside the app. RefundRadar never sees, reads, or stores your Temu password.
- Your Temu session stays on your device. After you sign in, your Temu session is held in the app's on-device storage and is used only to make requests to Temu. It is never transmitted to RefundRadar's servers.
- Credentials are encrypted at rest. The app's own account credential is stored in the platform secure store — the Android Keystore (via EncryptedSharedPreferences, AES-256) on Android and the iOS Keychain on iPhone.
What we send to our servers
The price checks and claims themselves run entirely on your device, directly with Temu — none of this is needed to find a drop or file a claim. We keep a copy on our servers to show your savings history and to run and improve the service:
- Order & item details (what you bought)
- Prices, and the refund amount when a drop qualifies
- A hashed identifier for your Temu account (we don't keep the original) plus an app-generated device ID
- Usage events (e.g. a scan ran, a claim was filed) so we can run and improve the service
What we never receive
- Your Temu password
- Your Temu session / login cookies
- Your payment card or how you pay
- Your delivery address
- Your phone number or inbox
How we test the app
We self-assess against the OWASP Mobile Application Security Verification Standard (MASVS) — the mobile-security baseline referenced by NIST, Germany's BSI and Google — and run free, open-source scanners on every release:
- Static analysis (mobsfscan): no insecure data storage, no cleartext transport, no crypto misuse
- Secret scanning (gitleaks): zero hardcoded keys or credentials in the app
- Transport security: App Transport Security enabled (iOS); traffic to our API is HTTPS-only
- Credential storage: tokens held in the Android Keystore / iOS Keychain
This is an honest self-assessment, not an OWASP-issued certification — OWASP does not certify apps, and we won't claim a badge we don't have. We publish the full scan — tools, exact commands, findings, remediation, permissions and dependencies, so anyone can reproduce it — in our latest security scan report (23 Aug 2026).
Report a vulnerability
Found something? We want to hear from you. See our security.txt or email hello@refundradar.co. We don't take legal action against good-faith security research.
More detail
For the full picture of what we collect and why, read our Privacy Policy. For terms of use, see our Terms.