Temu is not safe in the way most people mean it
Temu is a shopping app owned by a Chinese company called PDD Holdings. It is not unsafe because it will steal your money or infect your phone with malware in the traditional sense. It is unsafe because it collects far more personal information than most Western shopping apps, and that data goes to servers in China where U.S. privacy laws do not explore.
The real question is not whether Temu will crash your phone. The question is whether you are comfortable with a Chinese company having detailed records of what you browse, what you buy, where you are, what your contacts look like, and how you use your device — and whether you trust that company's security practices to keep that data from being breached or sold.
Key Takeaways
- Temu's app requests permission to access your location, contacts, photos, and device identifiers in ways that go beyond what is needed to sell you clothes and gadgets.
- Data collected by Temu is stored on servers in China, where Chinese law requires companies to hand over user information to the government if asked.
- Temu has experienced data breaches in the past, and security researchers have found the app sends information to multiple third-party companies without clear disclosure.
- The risk is not that Temu will drain your bank account, but that your personal information could be used for identity theft, targeted scams, or sold to data brokers.
- If you decide to use Temu, you can reduce exposure by using a separate email address, not linking your contacts, and disabling location access in your phone settings.
What permissions Temu asks for and why that matters
When you install Temu, the app requests access to your contacts, location, photos, clipboard, and device identifiers. Most of these requests are not necessary to buy a $3 t-shirt. Temu says it needs contacts to let you invite friends for referral bonuses, and location to show you local deals — but the app can do both of those things with much narrower access.
The clipboard access is particularly revealing. Temu reads what you copy and paste on your phone, which can include passwords, payment information, and text from private messages. There is no legitimate reason a shopping app needs this permission. Security researchers at Sensor Tower found that Temu was reading clipboard data far more often than necessary, sometimes dozens of times per session.
On Android phones, you can see which permissions Temu is using by going to Settings > Apps > Temu > Permissions. On iPhones, go to Settings > Privacy and scroll down to see what Temu can access. If you decide to use the app, you can deny most of these permissions and the app will still work — it will just nag you to turn them on.
Where your data goes and who can access it
Data collected by Temu is sent to servers in China. This is not inherently illegal, but it means your information is subject to Chinese law, not U.S. law. Under China's national security laws, the Chinese government can compel PDD Holdings to hand over user data without a warrant, without notifying you, and without you ever finding out it happened.
The U.S. government has expressed concern about this arrangement. In 2023, the Federal Trade Commission began investigating Temu's data practices. Several U.S. lawmakers have called for the app to be banned, arguing that the data collection poses a national security risk. None of these investigations have resulted in a ban, but they reflect genuine concern about what happens to American user data once it leaves U.S. servers.
Temu also shares data with third-party companies for analytics, advertising, and fraud detection. The app's privacy policy lists dozens of these partners, but does not always explain what data each one receives or how long they keep it. This is common in the app industry, but it means your information is in the hands of many companies, each with their own security practices and their own reasons to keep the data.
Past security breaches and what they exposed
In 2023, Temu experienced a data breach that exposed information on millions of users, including names, email addresses, and encrypted passwords. The breach was discovered by security researchers, not reported by Temu itself. The company did not publicly acknowledge the breach for weeks, and many users never found out their data was compromised.
This breach is not unique to Temu — most large apps have been breached at some point. But it shows two problems: first, that Temu's security is not perfect, and second, that the company is slow to tell users when something goes wrong. If your data is breached, you want to know quickly so you can change your password and watch for fraud. Temu's delay in disclosure meant users had no way to protect themselves.
The difference between Temu and other shopping apps
Apps like Amazon, eBay, and Walmart also collect personal data. They also ask for permissions and share data with third parties. The difference is that their data stays in the United States, where the Federal Trade Commission can investigate them, where users can sue them, and where Congress can pass laws to restrict them. If Amazon breaches your data, you have legal recourse.
With Temu, if something goes wrong, your options are limited. You cannot sue a Chinese company in U.S. court for violating your privacy. The FTC can investigate, but it has no power to enforce rules in China. If your data is stolen or sold, there is no legal remedy available to you. This asymmetry — where you have little power but high exposure — is the core of why security experts worry about Temu.
This does not mean Temu is uniquely evil. It means the structure of the company and the location of its servers create risks that are different from the risks of using American apps. Whether those risks are acceptable to you depends on your own tolerance for uncertainty and your assessment of how much your personal information is worth protecting.
How to reduce your exposure if you use Temu
If you decide to use Temu despite these concerns, you can take steps to limit what the app knows about you. Create a separate email address just for Temu, one that is not connected to your other accounts. Do not link your contacts or allow the app to access your phone's address book. Turn off location access in your phone's settings — Temu will still work, but it will not know where you are.
Do not use Temu's referral program, which requires you to share your contacts with the app. Do not link your social media accounts. Use a payment method that is not connected to your primary bank account — a prepaid card or a separate debit card is safer than your main checking account. This way, if your payment information is breached, the damage is limited.
Check your phone's clipboard access settings regularly. On Android, go to Settings > Apps > Temu > Permissions > Clipboard and make sure it is set to "Don't allow". On iPhone, Temu cannot access your clipboard without asking each time, but you can deny the request every time it appears. These steps do not eliminate the risk, but they reduce the amount of information Temu can collect about you.
What security researchers say about Temu's code
Security researchers who have examined Temu's code have found several concerning patterns. The app collects device identifiers that can be used to track you across the internet. It sends data to servers in multiple countries, not just China, which makes it harder to know where your information ends up. It uses obfuscation techniques — ways of hiding what the code is doing — which is common in malware but unusual in legitimate shopping apps.
None of these findings prove that Temu is stealing your data right now. But they show that the app is designed to collect as much information as possible and to hide what it is doing. This is a business model, not a bug. Temu makes money partly by selling cheap goods, but also by collecting and selling data about users. The more data it has, the more valuable you are to advertisers and data brokers.
Frequently Asked Questions
Will Temu steal my credit card number?
Temu's payment system is encrypted, so your credit card number is not transmitted in plain text. However, Temu has experienced breaches in the past, and storing payment information on any server creates risk. Using a prepaid card or a separate debit card limits your exposure if the payment database is breached.
Can Temu give my data to the Chinese government?
Yes. Chinese law requires companies to cooperate with government requests for user data. There is no legal process like a warrant, and companies cannot refuse or tell users they have been asked. This is the main reason U.S. security experts worry about Temu.
Is Temu illegal in the United States?
No, Temu is legal to read and use. However, the U.S. government has investigated its data practices, and some lawmakers have proposed banning it. As of now, there is no ban, but this could change.
What happens if I delete the Temu app?
Deleting the app removes it from your phone, but it does not delete the data Temu has already collected about you. The company still has records of your purchases, browsing history, and device information. You can request that Temu delete your account through the app's settings, though there is no way to verify that the deletion is complete.
Is TikTok Shop safer than Temu?
TikTok Shop is owned by ByteDance, a Chinese company, so it has similar data jurisdiction issues as Temu. However, TikTok has been operating in the U.S. longer and faces more regulatory scrutiny. The risks are comparable, though the details differ.