INDEX / DIRECTORY / TEMU / DIGITAL

Temu DIGITAL

DIGITAL INFRASTRUCTURE AUDIT UPDATED 2026-07-04
Digital Score 0.00 /10 E Temu - BDS-1000 47
Digital 0.00

Evidence-only forensic audit. Scoring happens downstream - see the main dossier for the composite assessment.

Forensic audits like this are reader-funded - no sponsors, no ads. Support OpenIntel →

Digital Audit - Temu

Domain: Digital - Digital / Technology Entity scope: Temu (the cross-border e-commerce marketplace operated by WhaleCo Inc., a subsidiary of PDD Holdings); PDD Holdings parent-level acts and the Pinduoduo China-domestic sibling app are documented and attributed at parent/sibling level except where evidence specifically ties them to Temu-brand infrastructure or data flows. Compiled: 2026-06-25 Method: Live web search only

Enterprise Technology Stack & Vendor Relationships

Temu’s publicly confirmed enterprise technology relationships are overwhelmingly with US-domiciled and Chinese-domiciled vendors. Google is the most documented technology partner: Temu has implemented multiple Google Web UI APIs - including Carousels, Popover, Anchor Positioning, and Customizable Select - reducing CPU load by 10–15% and was featured at Google I/O as a case study for enterprise-grade adoption of Google developer technologies.1 Temu’s app also ships with Firebase and integrates Google Analytics for mobile measurement.2 For advertising acquisition Temu ran one of the largest Meta (Facebook) and Google Ads campaigns in 2023, and the app deploys third-party tracking cookies from both platforms.3

Independent security analysis by Swiss cybersecurity firm NTC (December 2024) confirmed that the Temu app transmits encrypted JSON telemetry and embeds an undisclosed set of third-party analytics and advertising SDKs. The analysis also confirmed dynamic code loading, an extra proprietary encryption layer on top of HTTPS, and behaviour consistent with multiple SDK integrations, though the report stopped short of enumerating each named library.4 Separately, a security summary citing Trend Micro found that the Temu app includes multiple analytics and advertising SDKs, some linked to Chinese tech companies.5 Firebase (Google/US-domiciled) and Adjust are referenced in secondary reporting as embedded SDKs, but this has not been independently confirmed by a primary reverse-engineering report accessible to this audit; those references are therefore retained as unverified claims.

No Israeli-domiciled technology vendor has been identified in Temu’s confirmed enterprise stack. Two Israeli-founded but foreign-domiciled adtech firms - AppsFlyer (founded in Israel 2011; legal headquarters San Francisco, CA; operations centre Herzliya) and Taboola (founded in Israel 2007; headquarters New York City) - operate widely across e-commerce platforms, but no public source confirms either is integrated into Temu specifically. These are flagged as Israeli-founded, foreign (US)-domiciled; they are not treated as in-scope Israeli-domicile findings. Outbrain (founded in Israel 2006; headquarters New York City) is in the same category. No evidence of Temu using any of these three platforms was found. No evidence of Temu using any Israeli-domiciled vendor was found.6

Surveillance, Biometrics & Retail Technology

Multiple independent investigations and US state attorney general lawsuits have documented expansive surveillance-adjacent data collection by the Temu app. Allegations include keystroke logging, touch-gesture recording, screen interaction capture, clipboard access, and persistent device identifier harvesting.7 Arkansas was the first state to file suit (June 2024), alleging Temu’s app was “purposefully designed to gain unrestricted access” to a user’s phone including camera, location, contacts, and text messages.8 Texas, Nebraska, Kentucky, and Arizona subsequently filed similar suits.910 Nebraska’s June 2025 complaint is the most detailed publicly available filing and contains technical allegations about silent background data exfiltration.11

The NTC Swiss security report (December 2024) identified a proprietary encryption layer applied on top of HTTPS that makes independent traffic analysis difficult, specifically noting it obscures what data is being transmitted, how often, and to which destinations.4 The report did not find conclusive evidence of malicious activity but characterised the architecture as warranting caution. Grizzly Research (September 2023) published a more aggressive analysis - characterising Temu as “cleverly hidden spyware” with “the full array of characteristics of the most aggressive forms of malware/spyware” - but Grizzly is a short-seller with a financial interest in PDD Holdings’ stock price; its findings should be treated as an advocacy document corroborated only in part by independent sources.12

South Korea’s Personal Information Protection Commission (PIPC) found that Temu ran a February 2024 pilot programme in which it collected photo ID scans and facial biometric video recordings from Korean sellers; this constitutes a live biometric collection finding. The PIPC imposed a KRW 1.386 billion fine (approximately USD 978,000) in May 2025 for cross-border data transfers to Japan, Singapore, and China without user consent, and for the undisclosed biometric data collection.13

No Israeli-domiciled surveillance or biometric technology vendor relationship has been identified for Temu.

Cloud Infrastructure, Data Residency & Sovereign Cloud Participation

Temu’s privacy policy states that personal data may be transferred to and processed in China, Singapore, the United States, and other jurisdictions where PDD Holdings operates; it does not commit to regional data residency.14 Temu’s actual engineering and technology operations are centred in Guangzhou, Shanghai, and Shenzhen, with the Boston entity (WhaleCo Inc.) functioning principally as a legal and tax entity employing fewer than 20 staff.15

NOYB (None of Your Business), a European privacy rights organisation, filed GDPR complaints in 2024 against Temu and five other Chinese-operated apps - including TikTok, AliExpress, SHEIN, WeChat, and Xiaomi - for unlawful transfer of EU user data to China in the absence of an EU-recognised adequacy decision for China.16 Maximum exposure for Temu under GDPR was assessed by NOYB at approximately USD 1.35 billion (4% of global annual revenue). The underlying legal gap - China’s Personal Information Protection Law (PIPL) permitting state intelligence access without independent oversight, combined with no EU-China adequacy agreement - makes Standard Contractual Clause (SCC) reliance legally contested.14

Temu’s privacy policy states that EU-region user data is stored “within compliant cloud infrastructure” but does not name the cloud provider. No public source confirms which hyperscaler (AWS, Google Cloud, Azure, or Alibaba Cloud) hosts Temu’s EU-region infrastructure. The CSIS analysis noted that PDD Holdings’ links to People’s Data Management - a Beijing-controlled entity described as “the business front of the People’s Daily Public Opinion Data Centre” - create a plausible pathway for data generated by Temu to flow into CCP-controlled infrastructure, though this is structural inference rather than documented data-flow evidence.17

No Israeli sovereign cloud participation was identified.

Defence, Intelligence & Security Sector Technology Relationships

Temu has no publicly documented relationship with any defence, intelligence, or security sector entity. However, its data practices have attracted direct attention from US intelligence oversight:

In September 2024, 14 Republican members of the US House Permanent Select Committee on Intelligence - led by Rep. Darin LaHood (R-IL) - wrote formally to FBI Director Christopher Wray and SEC Chair Gary Gensler requesting a classified briefing on Temu and PDD Holdings. The letter cited concerns about zero-day exploitation by the Pinduoduo sibling app (Google Play suspension, March 2023) and asked whether the FBI had provided any intelligence to the SEC regarding Temu.18 The House Intelligence Committee letter is a governmental threat-assessment action, not evidence of Temu being contracted to any intelligence body.

The CSIS Strategic Technologies Program published a standalone analysis of Temu in October 2024, recommending that the FTC investigate Temu for deceptive practices and that the Department of Commerce’s ICTS office assess its national security risks, explicitly comparing its threat profile to TikTok.17 CSIS is a non-governmental think tank; its recommendations are not binding.

Pinduoduo app - sibling attribution: Google suspended Pinduoduo from the Play Store in March 2023 after versions of the app outside the Play Store were found to exploit Android zero-day vulnerabilities allowing device control. Google’s statement confirmed the ban did not extend to Temu at the time.19 This incident is contextual to the parent company’s track record but does not constitute a Temu-brand finding.

No Temu engagement with Israeli defence, intelligence, or security vendors was identified.

AI, Algorithmic & Autonomous Systems

Temu’s platform is driven by a proprietary real-time deep learning recommendation system that analyses user behaviour, purchase history, and session data to personalise product rankings, pricing displays, and promotional placement.20 The EU Digital Services Act investigation opened against Temu in October 2024 specifically includes a strand examining “recommender system transparency” - the DSA requires very large online platforms to explain their recommendation logic; Temu’s failure to disclose this system adequately is one of four ongoing investigation strands.21

The EU’s May 2026 €200 million DSA fine - the largest imposed under the DSA to date - was issued specifically for Temu’s failure to assess how the design of its service, including recommender systems and influencer product-promotion programmes, could amplify the dissemination of illegal products.22 Three additional investigation strands covering addictive design features (gamification / dark patterns), recommender transparency, and researcher data access remain open as of June 2026.21

A study by the Federation of German Consumer Organisations confirmed that Temu uses dark pattern mechanics including gamified elements (mandatory “spin the fortune wheel” before accessing the marketplace), countdown timers, and intrusive notifications to engineer compulsive engagement.23 The EU Commission’s preliminary findings cited this as a separate potential violation under DSA Article 25 (prohibited dark patterns for very large platforms).

No Israeli AI or algorithmic system vendor was identified in Temu’s confirmed technology stack.

Technology Ecosystem & R&D Footprint

Temu’s confirmed R&D and engineering presence is exclusively in China. Core technology teams - including those responsible for the recommendation engine, logistics optimisation, and app development - are located in Guangzhou, Shanghai, and Shenzhen, under PDD Holdings’ broader engineering organisation.15 Temu has no confirmed R&D office, technology centre, or technology partnership in Israel.

PDD Holdings invested substantially in AI-driven logistics and demand-forecasting systems in FY2024, contributing to a 59% year-on-year revenue increase to USD 53.96 billion. Research and development investment is disclosed in PDD Holdings’ SEC 20-F filing (fiscal year ending December 31, 2024), but is not itemised by product line or location.24

Fortune (April 2024) investigated Temu’s nominal US headquarters at 31 St. James Avenue, Suite 355, Boston, MA, finding it functions primarily as a legal registration address with fewer than 20 employees; no US-based technology R&D was identified.15

AppsFlyer note (Israeli-founded, US-domiciled): AppsFlyer, an Israeli-founded mobile attribution platform (Herzliya R&D base, San Francisco headquarters), is widely used by e-commerce apps globally and has been referenced in secondary reporting on Temu’s SDK stack, but this has not been confirmed by a primary technical analysis accessible to this audit. AppsFlyer is Israeli-founded but is incorporated and headquartered in the United States and is therefore not an Israeli-domiciled vendor. No in-scope Israeli technology R&D relationship was confirmed.

Civil Society Scrutiny & Regulatory History

The regulatory and civil society record against Temu is one of the most extensive of any e-commerce platform operating internationally:

United States: Multiple US state attorneys general have filed suit. Arkansas (June 2024) was first, followed by Texas, Nebraska (June 2025), Kentucky (July 2025), and Arizona (December 2025).7910 All allege unlawful covert data harvesting. The FTC obtained a $2 million civil penalty and injunction against Whaleco Inc. (Temu) in September 2025 for violations of the INFORM Consumers Act.25 The House Intelligence Committee formally requested FBI and SEC briefings on Temu’s national security risk (September 2024).18

European Union: The European Commission opened formal DSA proceedings in October 2024.21 Preliminary findings issued in July 2025 found Temu in breach of systemic risk-assessment obligations. The Commission issued a €200 million fine on 28 May 2026 - the largest DSA fine issued to date - for failures around illegal products, recommender system amplification, and influencer promotion programmes.22 Three additional investigation strands remain open.

South Korea: PIPC fined Temu KRW 1.386 billion (approximately USD 978,000) in May 2025 for cross-border data transfers without consent and biometric data collection without disclosure.13

European data protection authorities: NOYB filed GDPR complaints in 2024 with data protection authorities in Greece, Italy, Belgium, the Netherlands, and Austria for unlawful transfer of EU user data to China.16 Those proceedings are ongoing.

Switzerland: NTC (National Test Center for Cybersecurity) published an independent technical security analysis of the Temu app in December 2024, identifying anomalies (dynamic code loading, proprietary encryption obfuscation) but stopping short of characterising the app as malicious. NTC recommended against use in business and government contexts.4

End Notes

Footnotes

  1. https://cxmtoday.com/news/temu-taps-googles-tech-for-enhancing-on-screen-experience/

  2. https://techbuzzchina.substack.com/p/temu-watch-5-logistics-marketing

  3. https://smarter-ecommerce.com/blog/en/analytics/google-meridian-and-temu-ad-shift/

  4. https://en.ntc.swiss/news/2024-security-analysis-temu 2 3

  5. https://negg.blog/en/temu-app-security-under-fire/

  6. https://ensun.io/search/adtech-and-martech/israel

  7. https://www.dataprivacyandsecurityinsider.com/2025/07/privacy-tip-452-temu-tiktok-assess-risk-before-downloading/ 2

  8. https://finance.yahoo.com/news/temu-faces-lawsuit-privacy-violations-133747721.html

  9. https://allaboutlawyer.com/temu-lawsuits-explode-in-2025-multiple-states-lawsuits-over-data-theft-business-allegations/ 2

  10. https://www.azag.gov/press-release/attorney-general-mayes-sues-online-shopping-platform-temu-stealing-arizonans-data-and 2

  11. https://ago.nebraska.gov/attorney-general-hilgers-files-lawsuit-against-temu-siphoning-nebraskans-phone-data

  12. https://grizzlyreports.com/we-believe-pdd-is-a-dying-fraudulent-company-and-its-shopping-app-temu-is-cleverly-hidden-spyware-that-poses-an-urgent-security-threat-to-u-s-national-interests/

  13. https://www.cpomagazine.com/data-protection/temu-privacy-law-violations-over-south-korean-data-transfer-rules-land-a-982000-fine/ 2

  14. https://www.notebookcheck.net/Data-privacy-at-risk-TikTok-Temu-and-Xiaomi-s-illegal-data-transfer-to-China-scrutinized-by-digital-rights-organization.948602.0.html 2

  15. https://fortune.com/2024/04/26/temu-shopping-app-china-us-headquarters/ 2 3

  16. https://www.bleepingcomputer.com/news/security/gdpr-complaints-filed-against-tiktok-temu-for-sending-user-data-to-china/ 2

  17. https://www.csis.org/analysis/looking-beyond-tiktok-risks-temu 2

  18. https://cyberscoop.com/house-intelligence-republicans-temu-pinduoduo-zero-day/ 2

  19. https://krebsonsecurity.com/2023/03/google-suspends-chinese-e-commerce-app-pinduoduo-over-malware/

  20. https://www.shaped.ai/blog/how-does-temu-work

  21. https://ec.europa.eu/commission/presscorner/detail/en/ip_24_5622 2 3

  22. https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1178 2

  23. https://www.vzbv.de/en/amazon-tiktok-temu-manipulative-designs-remain-problem

  24. https://www.sec.gov/Archives/edgar/data/1737806/000141057825000951/pdd-20241231x20f.htm

  25. https://www.justice.gov/opa/pr/temu-agrees-2m-civil-penalty-and-injunction-alleged-violations-inform-consumers-act