4 Sources
[1]
Engineer proves that Kohler's smart toilet cameras aren't very private
Kohler is facing backlash after an engineer pointed out that the company's new smart toilet cameras may not be as private as it wants people to believe. The discussion raises questions about Kohler's use of the term "end-to-end encryption" (E2EE) and the inherent privacy limitations of a device
[2]
Kohler's Poop-Analyzing Toilet Cam Might Also Flush Your Privacy Down the Drain
A toilet camera that can analyze your poop isn't as private as its marketing suggests. In October, Kohler Health announced the Dekoda, a $599 camera that hangs on the rim of your toilet and analyzes your stool and urine for potential health insights. Obviously, the product raised questions about
[3]
Kohler's $600 AI toilet camera sparks major privacy concerns
Serving tech enthusiasts for over 25 years. TechSpot means tech analysis and advice you can trust. Talking crap? Remember the Dekoda, the $600 (plus subscription fee) AI-infused camera that attaches to the inside of your toilet and photographs your stools? It seems that maker Kohler's claim that
[4]
Kohler's Smart Toilet Camera Not Actually End-to-End Encrypted
Home goods company Kohler would like a bold look in your toilet to take some photos. It's OK, though, the company has promised that all the data it collects on your "waste" will be "end-to-end encrypted." However, a deeper look into the company's claim by technologist Simon Fondrie-Teitler revealed
Share
Copy Link
Kohler's $599 Dekoda smart toilet camera promised end-to-end encryption for health data collected from users' waste. But former Federal Trade Commission advisor Simon Fondrie-Teitler discovered the company can access and decrypt user data on its servers, contradicting typical E2EE standards. The revelation raises questions about misleading privacy claims in smart home devices.
Kohler is facing intense scrutiny after a former Federal Trade Commission technology advisor exposed misleading privacy claims about its new AI-powered toilet camera
1
. The $599 Dekoda smart toilet attachment, launched in October by Kohler Health, uses optical sensors and machine-learning algorithms to analyze stool and urine for health insights1
. The device requires a subscription starting at $7 per month and promises "end-to-end encryption" for user data privacy1
.
Source: Ars Technica
Simon Fondrie-Teitler, a software engineer and former FTC advisor, began investigating after noticing the company's E2EE claims seemed inconsistent with what Kohler collected according to its privacy policy
4
. His analysis revealed that Kohler can access and decrypt user data on its servers, fundamentally contradicting what end-to-end encryption means in consumer technology2
.E2EE is most commonly associated with messaging apps like Signal and WhatsApp, where only the sender and recipient can decrypt messages
1
. The service provider cannot access the content, which prevents third parties, including law enforcement, from reading private communications2
. This protection is what consumers expect when they see "end-to-end encryption" advertised.However, emails exchanged between Fondrie-Teitler and Kohler's privacy team clarified that "the other 'end' that can decrypt the data is Kohler themselves"
1
. The company confirmed that "user data is encrypted at rest, when it's stored on the user's mobile phone, toilet attachment, and on our systems. Data in transit is also encrypted end-to-end, as it travels between the user's devices and our systems, where it is decrypted and processed to provide our service"1
.Kohler Health issued a statement defending its use of the term, arguing that it applied E2EE "with respect to the encryption of data between our users (sender) and Kohler Health (recipient)"
1
. The company acknowledged that it's not a messaging application and used the term differently than typical consumer applications4
.What Kohler describes is actually Transport Layer Security or HTTPS encryption, which has been standard security practice for two decades
3
. As IBM defines it, Transport Layer Security "encrypts data as it travels between a client and a server. However, it doesn't provide strong protection against access by intermediaries such as application servers or network providers"1
.The Dekoda's privacy policy reveals Kohler Health collects "health data, including fecal and urine images" along with sensor information about "gut health and blood in bowl"
2
. More concerning, the policy states the company can use this data and share it with third parties to refine its platform, improve products, promote its business, and train AI and machine-learning algorithms3
.Kohler Health confirmed to media outlets that if users consent through an optional, unchecked checkbox in the app, the company may de-identify the data and use it to train AI programs
2
. The company emphasized that "privacy and security are foundational to Kohler Health because we know health data is deeply personal"2
.Related Stories
RJ Cross, director of the consumer privacy program at the Public Interest Research Group, told Ars Technica that "using terms like 'anonymized' and 'encrypted' gives an impression of a company taking privacy and security seriously -- but that doesn't mean it actually is"
1
. The misleading privacy claims echo a similar case where Zoom faced Federal Trade Commission fines for falsely advertising E2EE capabilities4
.Fondrie-Teitler explained his motivation for investigating: "I'd like the term 'end-to-end encryption' to not get watered down to just meaning 'uses https' so I wanted to see if I could confirm what it was actually doing and let people know"
4
. He emphasized that maintaining clear definitions helps consumers make informed decisions about data privacy in an already complex landscape of smart home devices.The controversy highlights broader issues with how companies market privacy features in connected devices. Fondrie-Teitler noted that "it's already so hard for non-technical individuals (and even tech experts) to evaluate the privacy and security of the software and devices they're using"
4
. When companies blur the meaning of established security terms, it becomes even harder for consumers to understand what protections they actually have.The Dekoda's primary competitor, Throne, uses similarly vague language, claiming "bank-grade encryption" without specifying E2EE
1
. This suggests the problem extends beyond Kohler to an emerging category of wellness-focused smart home devices that collect highly sensitive health data. As these products become more common, the need for clear, accurate privacy disclosures becomes increasingly critical for protecting user data privacy and maintaining trust in health insights technology.Summarized by
Navi
22 Oct 2024•Technology

03 Mar 2026•Policy and Regulation

01 Sept 2026•Technology

1
Technology

2
Technology

3
Policy and Regulation
