Home / Technology  / A Public Toilet Should Not Need a User Journey

A Public Toilet Should Not Need a User Journey

Editorial photograph of a freestanding modular public toilet on a New York City sidewalk, an adult.

A Public Toilet Should Not Need a User Journey

A bladder does not care about your onboarding flow. A child cannot postpone an accident until a verification code arrives. Someone managing Crohn’s disease does not need a more delightful interface; they need an open door. Public sanitation is where the language of frictionless technology meets a body that cannot negotiate.

Dwell’s report on New York City’s new app-based public toilets brings this collision into focus. Modular bathrooms promise something the city desperately needs: more places to go. Digital management may make those facilities easier to operate. But neither proposition answers the decisive question: can someone use the toilet immediately without a functioning smartphone?

The source summary establishes an app-based approach, not the complete access protocol. It does not establish whether every visit requires registration, payment, or connectivity, or what alternative entry exists. Those distinctions matter. The criticism is not that every possible digital obstacle has already occurred. It is that public infrastructure must demonstrate its fallback before an app becomes its front door.

A journey is something you choose to undertake. Urgent sanitation is a service the city should already have made available when you arrive.

The Operator’s Dashboard Is Not the Public Realm

Close editorial photograph at the entrance of a modular public bathroom in New York City.

There are legitimate reasons to connect a toilet to software. Operators can monitor faults, coordinate cleaning, identify supply shortages, and check whether a unit is occupied. A modular facility can potentially be installed where a conventional building would demand more time and construction. These are useful capabilities, not evidence of a conspiracy against pedestrians.

The mistake is allowing the maintenance system to dictate the admission system. An operator may prefer a registered user because an account offers a mechanism for communication or enforcement. A visitor may prefer not to establish a relationship with a technology company simply to urinate. When the facility occupies public space, the second preference deserves more than a customer-service workaround.

Paris’s longstanding network of automated public toilets offers a useful distinction: automation need not mean personal authentication. Machinery can manage cleaning cycles and occupancy without requiring the person outside to become a platform user.

Don Norman’s writing on human-centered design repeatedly returns to intelligibility: people should understand what an object allows them to do. A public toilet’s interface should communicate availability, entry, locking, and exit. If the operational complexity spills onto the pavement as account recovery or permission requests, the design has not eliminated friction. It has outsourced friction to the person least able to absorb it.

A Smartphone Is Not an Accessibility Standard

Imagine three entirely ordinary visitors to a New York sidewalk bathroom: a delivery worker whose phone battery is nearly exhausted, a tourist without a working data connection, and an older resident who uses a basic mobile phone. None is an edge case. They are the public. A system that treats their entry as an exception has defined its audience too narrowly. It also raises the question of who decides which phone apps are essential.

Nor does smartphone ownership guarantee usable access. Glare can make a screen difficult to read. Tremor can make precise tapping difficult. A blind visitor may encounter an inadequately labeled app control. A parent managing a stroller and a distressed child may have no free hand for a download. These are foreseeable design conditions, not failures of user preparedness.

Architect Ronald Mace’s universal-design framework offers a better starting point: equitable use, simple operation, perceptible information, and low physical effort. Applied here, those principles mean the non-app route must be obvious, accessible, and available during the same operating hours—not hidden behind a support number.

The physical bathroom still matters: turning space, grab bars, reachable controls, clear signage. But an accessible interior behind an inaccessible admission process is an architectural contradiction. Digital access belongs in the accessibility review, not in a separate procurement appendix marked innovation.

New York Already Knows That Service Is Design

Wide editorial photograph of routine maintenance inside a compact modular public toilet in New York City.

The public restrooms at Bryant Park demonstrate a less fashionable proposition: sanitation quality depends on sustained care. Their reputation rests on an attended, maintained environment, not merely the specification of fixtures. The lesson is not that every neighborhood toilet needs decorative flourishes. It is that staffing and upkeep are design decisions with consequences as tangible as wall materials.

The Tokyo Toilet project makes a complementary argument. Its facilities, including designs by Shigeru Ban and Tadao Ando, treat the public bathroom as architecture worthy of attention rather than an embarrassing utility to conceal. Yet even celebrated architecture cannot substitute for dependable cleaning, intelligible operation, and access that works for unfamiliar visitors.

New York should resist the temptation to confuse a photogenic modular enclosure with a complete public service. The enclosure is one component. Site selection, opening hours, supplies, repair times, and the person responsible when a door will not open are the rest of the project.

An app can help coordinate that work. It cannot make the work disappear. If software savings are achieved by removing assistance at precisely the moments users need it, the city has not become more efficient. It has moved the cost into embarrassment, delay, and exclusion—outcomes that rarely appear on the operator’s dashboard.

The Fallback Must Be Part of the Contract

The minimum guarantee should be straightforward: walk-up entry without a personal device, account, or digital payment credential. A physical control should make the request legible. Local door controls should distinguish an occupied cubicle from an available one without depending on a visitor’s connection. Clear, accessible indicators should explain whether the facility is ready, cleaning, occupied, or out of service.

Fallback does not mean unlocking an occupied toilet during a network failure. Privacy and safe exit are nonnegotiable. It means designing the admission system so that a service outage need not become an access outage where the facility remains safe and functional. Any emergency override must protect occupants and follow applicable safety requirements.

Where a unit genuinely cannot operate safely, the response must be more than an error message. Post directions to the nearest available alternative, including its distance and hours. Set contractual repair deadlines. Provide reachable human assistance, but do not pretend a telephone number is equivalent to an open door.

Procurement should test these conditions in person. Ask a bidder to demonstrate a visit with no phone, a disconnected network, and a user who needs accessible controls. Measure successful entry and restoration time, not just app adoption. Any required power backup should follow a documented safety assessment rather than a marketing promise of uninterrupted service.

Do Not Turn Bodily Need Into a Data Product

Digital sanitation also raises a question that architecture briefs too often overlook: what must the system know about the visitor? Occupancy and maintenance information can have clear operational value. A persistent identity attached to bathroom visits requires a much stronger justification. As with turning garbage trucks into building inspectors, the question is how far a public service’s data-gathering role should extend.

Not every app necessarily collects the same information, and the available source summary does not establish this system’s data practices. That uncertainty is an argument for explicit rules. Public contracts should require data minimization, defined retention periods, and transparency about third-party access. Anonymous operational counts should be preferred wherever they meet the service need. Marketing consent has no place in the route to an essential toilet.

There is a deeper political choice here. Cities can treat sanitation as a universal service whose technical systems remain largely backstage. Or they can treat it as a sequence of individually authorized transactions, with each person responsible for arriving digitally equipped.

Mainifesto’s position is the former. Apps should help people locate facilities, check availability, or report faults. They should not become compulsory passports to bodily dignity. The genuinely advanced public toilet is not the one that knows its users best. It is the one that remains useful when it knows nothing about them.

FAQ

Are app-based public toilets inherently bad design?

No. Apps can support maintenance, wayfinding, and fault reporting. The problem begins when essential access depends on a personal device or account rather than an equally usable walk-up option.

What fallback access should a public toilet guarantee?

It should provide clearly marked, accessible entry without a smartphone or account whenever the facility is operational. Door systems must preserve occupancy privacy and safe exit. Closures need visible alternative locations and a defined repair response.

Can toilets remain secure without identifying every visitor?

Identification is not the only security tool. Robust fixtures, occupancy controls, appropriate time limits, maintenance, and attendants can address different risks. Measures should be proportionate and must not endanger or penalize people who need longer visits.

How should cities measure whether digital toilets work?

Measure availability, cleanliness, successful phone-free entry, accessibility, fault-resolution time, and user complaints. Downloads and registered accounts measure platform uptake, not whether people can reliably use a public toilet.

If a public toilet works seamlessly for its operator but leaves a person without a phone outside, whose convenience has the city actually designed for?

Watch the Mainifesto Short

Watch on YouTube

Enjoyed this perspective?

Get the Mainifesto weekly — curated design debates, speculative ideas and the week's best articles every Saturday.

Editorial Perspectives

Questions and counterpoints developed by the Mainifesto editorial desk to extend the discussion.

Perspective 1

If the access model assumes a charged phone and a working network, it has designed out a predictable part of the public. We test buildings under peak loads and emergency conditions; why not test this threshold with someone who has no account, no signal, and no time?

Perspective 2

Put the smart technology behind the scenes: flag leaks, coordinate cleaning, keep the toilet working. Let people open the door without a digital introduction—the future of public infrastructure should demand less from us, not another login.

Perspective 3

I'd want to see failed entries and time-to-access, not just successful unlocks on an operator dashboard. A sleek unit with a phone-only lock is still a poor specification; offline access needs to be built, costed, and maintained from day one.

NO COMMENTS

POST A COMMENT