The shared device: what signing out does and does not clear
Every other page in this desk assumes the device is yours. This one does not, and it is the page where the two clocks, the token and the recheck all meet.
- closed the tab
- not a sign-out
- token
- 30 days
- returned after
- 3 hours
- still signed in
- 1 of 1
On a shared device, closing the tab, closing the browser or walking away does not end the session or remove a persistent sign-in. On the samples a tab closed at 10:11 and reopened three hours later came back signed in, because the token was never revoked. Signing out is the action that removes it, and it is the only one of the published endings that a reader controls directly.
Closing the tab is not on the list
Sample F is one invented rules document that publishes five ways a session can end. Closing the tab is not among them, and the record shows it as what it is: nothing.
| Ending | Started by | Removes the token |
|---|---|---|
| the idle clock | time | no |
| the absolute lifetime | time | no |
| signing out | you | yes |
| the concurrency limit | another sign-in | no |
| a revocation (password change, lost device) | you | yes |
| closing the tab | you | no - not an ending at all |
| 5 published | 0 of 5 are the tab | 2 of 5 remove the token |
The three things worth doing
The first is to sign out, which is the only ending on the list that a reader starts deliberately and that removes the token. The second is not to tick stay signed in on a machine that is not yours, because a 30-day token is the thing the next person inherits. The third is to remember that within a live session a deposit and a bet are not rechecked, so a session left open is a usable account for anyone at that keyboard - the recheck protects money leaving and the password, not the stake.
Private or incognito modes change less than people expect: they may discard the token when the window closes, and they may not, and the desk's samples do not treat them as an ending. The reliable action on the list is still the sign-out.
- Sign out at the end of a shared-device session; closing the window is not on the published list of endings.
- Do not tick stay signed in on a machine you do not own, whatever the device is.
- Assume a live session can place a bet and take a deposit without a second password.
- Check the session record afterwards if the machine is genuinely public, and use sign-out-everywhere if anything looks unfamiliar.
- Do not treat a private window as a sign-out: signing out is the action that removes the token.