Categories Technology

‘End-to-end encrypted’ smart toilet camera is not actually end-to-end encrypted

Earlier this year, home goods maker Kohler launched a smart camera called the Dekoda that attaches to your toilet bowl, takes pictures of it, and analyzes the images to advise you on your gut health. 

Anticipating privacy fears, Kohler said on its website that the Dekoda’s sensors only see down into the toilet, and claimed that all data is secured with “end-to-end encryption.”

The company’s use of the expression “end-to-end encryption” is, however, wrong, as security researcher Simon Fondrie-Teitler pointed out in a blog post on Tuesday. 

By reading Kohler’s privacy policy, it’s clear that the company is referring to the type of encryption that secures data as it travels over the internet, known as TLS encryption — the same that powers HTTPS websites. 

Using the right terms matters, especially in the context of users’ privacy concerns. Using the expression end-to-end encryption — widely adopted by messaging apps such as iMessage, Signal, and WhatsApp — to describe TLS encryption is wrong, and can potentially confuse users who see that expression and think Kohler actually cannot see the pictures that the camera takes. 

A Kohler spokesperson did not respond to questions from TechCrunch, but a company “privacy contact” told Fondrie-Teitler that user data is “encrypted at rest, when it’s stored on the user’s mobile phone, toilet attachment, and on our systems.” The company also said that, “data in transit is also encrypted end-to-end, as it travels between the user’s devices and our systems, where it is decrypted and processed to provide our service.”

The security researcher also pointed out that given Kohler can access customers’ data on its servers, it’s possible Kohler is using customers’ bowl pictures to train AI. Citing another response from the company representative, the researcher was told that Kohler’s “algorithms are trained on de-identified data only.”

Techcrunch event

Join the Disrupt 2026 Waitlist

Add yourself to the Disrupt 2026 waitlist to be first in line when Early Bird tickets drop. Past Disrupts have brought Google Cloud, Netflix, Microsoft, Box, Phia, a16z, ElevenLabs, Wayve, Hugging Face, Elad Gil, and Vinod Khosla to the stages — part of 250+ industry leaders driving 200+ sessions built to fuel your growth and sharpen your edge. Plus, meet the hundreds of startups innovating across every sector.

Join the Disrupt 2026 Waitlist

Add yourself to the Disrupt 2026 waitlist to be first in line when Early Bird tickets drop. Past Disrupts have brought Google Cloud, Netflix, Microsoft, Box, Phia, a16z, ElevenLabs, Wayve, Hugging Face, Elad Gil, and Vinod Khosla to the stages — part of 250+ industry leaders driving 200+ sessions built to fuel your growth and sharpen your edge. Plus, meet the hundreds of startups innovating across every sector.

San Francisco
|
October 13-15, 2026

The Dekoda costs $599 plus a mandatory subscription of at least $6.99 per month.

Original Source: https://techcrunch.com/2025/12/03/end-to-end-encrypted-smart-toilet-camera-is-not-actually-end-to-end-encrypted/

Disclaimer: This article is a reblogged/syndicated piece from a third-party news source. Content is provided for informational purposes only. For the most up-to-date and complete information, please visit the original source. Digital Ground Media does not claim ownership of third-party content and is not responsible for its accuracy or completeness.

More From Author

Leave a Reply

Your email address will not be published. Required fields are marked *