Kohler has faced scrutiny over its misleading claims regarding the privacy protections in its $600+ Dekoda smart toilet camera system.
The company prominently advertises “end-to-end encryption” across its official websites and marketing materials, suggesting that user data is protected from all external access including Kohler itself.
However, recent technical clarifications from the company reveal a fundamental misrepresentation of how the system actually secures sensitive health and biometric data collected from users’ bathrooms.
Understanding the Encryption Gap
End-to-end encryption (E2EE) is a cryptographic standard where only the message sender and intended recipient possess the keys to decrypt data.
When correctly implemented as in Signal, WhatsApp, or iMessage it prevents even the application developer from accessing private communications.
This protection extends beyond normal security measures; if a company’s servers are compromised, encrypted data remains unreadable to attackers.
Kohler’s implementation falls drastically short of this standard. According to correspondence with the company’s privacy team, Kohler retains the ability to access and decrypt all data collected by Dekoda devices.
The company stated that data “is decrypted and processed” on Kohler’s servers “to provide our service.”
What Kohler describes as “end-to-end encryption” is actually HTTPS encryption the basic security protocol websites have used for two decades combined with encryption at rest.
This distinction is critical: HTTPS protects data in transit, but Kohler maintains access to decrypted data once it reaches their servers.
The privacy implications extend beyond false encryption claims. Kohler’s privacy policy explicitly permits using collected data including bathroom images and biometric information to train artificial intelligence and machine learning models.
During account setup, users are pressured to consent to data collection for “research, develop, and improve its products and technology.”
The company claims algorithms are trained on “de-identified data only,” yet the legal language remains vague about what de-identification actually entails and how effectively it prevents re-identification of sensitive bathroom imagery.
Kohler additionally states that de-identified data may be shared with unspecified third parties for “lawful business purposes,” creating opacity around who ultimately accesses toilet imaging data.
Multiple prominent tech media outlets, including CNET, The Verge, and TechCrunch, repeated Kohler’s end-to-end encryption claims in launch coverage, unknowingly amplifying the company’s misrepresentation.
Kohler Health’s homepage, app description, and support documentation all use the term “end-to-end encryption” despite the company’s clear technical inability to prevent their own access to sensitive health data.
Find this Story Interesting! Follow us on Google News, LinkedIn and X to Get More Instant Updates