Security

How RefundRadar protects your data · last reviewed August 2026

The short version

Your Temu login stays on your phone, and the price checks and claims run entirely on your device, talking directly to Temu — we never see your password or your Temu session, and Temu itself rejects duplicate claims. Finding a drop and claiming it never requires your data to leave your phone. We do keep a copy of your order and refund data on our servers — to show your savings history across your devices and to run and improve the service — and we back it all with free, automated security scans against the OWASP MASVS mobile-security standard.

At a glance

Current version
1.0.25
iOS
App Store · id6778789358
Android package
co.refundradar
Last tested
23 Aug 2026

Your Temu login

What we send to our servers

The price checks and claims themselves run entirely on your device, directly with Temu — none of this is needed to find a drop or file a claim. We keep a copy on our servers to show your savings history and to run and improve the service:

What we never receive

How we test the app

We self-assess against the OWASP Mobile Application Security Verification Standard (MASVS) — the mobile-security baseline referenced by NIST, Germany's BSI and Google — and run free, open-source scanners on every release:

This is an honest self-assessment, not an OWASP-issued certification — OWASP does not certify apps, and we won't claim a badge we don't have. We publish the full scan — tools, exact commands, findings, remediation, permissions and dependencies, so anyone can reproduce it — in our latest security scan report (23 Aug 2026).

Report a vulnerability

Found something? We want to hear from you. See our security.txt or email hello@refundradar.co. We don't take legal action against good-faith security research.

More detail

For the full picture of what we collect and why, read our Privacy Policy. For terms of use, see our Terms.