Discover a new way of working, where flexibility and security go hand in hand. Work as much as you want for the clients you find interesting, on a temporary employment contract for each shift.
This app did not meet two or more trust checks, has a critical issue in one, or carries a red flag.
The five trust checks
Quick Verdict
Best for: Booking and managing flexible work shifts
What It Means For You
AppsFlyer, Mixpanel, and Sentry are gated behind in-app consent and do not load until the user grants permission. When the user consents to Mixpanel, analytics data is routed to EU-region servers. Usage and device data is also shared with Firebase, Intercom, and Salesforce Marketing Cloud as part of the service.
Quick Verdict
Best for: Booking and managing flexible work shifts
What It Means For You
AppsFlyer, Mixpanel, and Sentry are gated behind in-app consent and do not load until the user grants permission. When the user consents to Mixpanel, analytics data is routed to EU-region servers. Usage and device data is also shared with Firebase, Intercom, and Salesforce Marketing Cloud as part of the service.
Method and Limitations
Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.
Data Security
1 totalNetwork Security
2 totalCode Security
3 totalVersion diff is on the Developer plan. See developer plans.
Context Tags
Package
temper.worker.android
Version
1.21.2 (versionCode 290)
Analysis Date
Aug 12, 2026
Feedback helps us improve our analysis
CITT rates this build Solid: the login flow uses a robust authorization code method that limits the impact of code interception, API communications are well-secured, and three analytics services require explicit consent before receiving any data. Weighed against those strengths are preconsent data flows to Firebase, Salesforce Marketing Cloud, and Intercom, and account and location data stored without encryption on the device.
Data Security: 1 finding (1 medium)
Network Security: 2 findings (2 medium)
Code Safety: 3 findings (2 medium, 1 low)
Privacy: 0 findings
No sensitive data was identified as processed only on the device in this analysis.
Third parties that may receive data from the app:
Security: 85/100
Privacy: 65/100
Observations about disclosure, each stated against the published guidance so a reader can compare:
Preconsent data routing on first launch
Google Play's Data Safety guidance (retrieved 2026-08-12) requires disclosure when personal data is shared with third parties. The binary links Firebase Analytics, Salesforce Marketing Cloud, and Intercom in configurations that appear capable of routing device and account data before the in-app consent prompt is shown on first launch. Whether server-side controls prevent data from reaching those services before consent is granted could not be determined from static analysis alone.
Beacon proximity infrastructure not reflected in Play Store label
The binary includes AltBeacon and the Salesforce Marketing Cloud proximity SDK, libraries associated with Bluetooth beacon-based location tracking. The Google Play Data Safety label (retrieved 2026-08-12) does not name proximity or beacon tracking among the data types shared with third parties. Whether these libraries route location data at runtime could not be determined from static analysis.
Install attribution recipient not named in Play Store label
The binary links AppsFlyer, configured to receive the advertising identifier when the user grants consent. The Play Store Data Safety label (retrieved 2026-08-12) discloses that "Personal info" may be shared with third parties but does not name AppsFlyer as a recipient by name.
Expand backup exclusions to cover account and session data files
The current backup configuration excludes only AppsFlyer-specific files. Expanding the exclusion rules to cover account preference files and session data storage would prevent those files from being copied to cloud backup or restored to a different device.
Restrict mixed-content loading in in-app messaging views
The Intercom in-app messaging component allows HTTP resources within HTTPS pages in its views. Configuring those views to reject HTTP subresources would reduce the risk of network-based content injection affecting in-app actions.
Remove testing framework components from production builds
This release build includes testing framework activities that any co-installed app can start without restriction. Ensuring debug-only dependencies are excluded from the production build configuration would reduce the exposed surface area.
App Type: Business - gig work and temporary employment platform (sensitive: employment, financial, biometric, location data)
Classes Analyzed: 0
Third-Party Services: 16
Context Tags: employment, financial, sensitive_data, location, ads, biometric
This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. The analysis is static code review of Android applications, intended to help people make informed decisions about app security and privacy.
Developer: Temper IP B.V.
Version: 1.21.2 (versionCode 290)
Analysis Date: 2026-08-12
Package: temper.worker.android
Developer not yet contacted