H6.07.3conspicuous sign-out on shared devicesdesignresearch

Shared devices need a conspicuous sign-out prompt

Aliases: public computer logout · kiosk sign-out · borrowed device

What it is

On a personal phone, sign-out is rare; on a library computer, store tablet, borrowed family device, or a demo on a projector, not signing out leaves the session for the next person. A conspicuous sign-out prompt means that in contexts the product can judge as shared or temporary, “sign out when you are done” is placed at task end, idle timeout, and close—not assumed to be found in a menu. This entry is about when the reminder appears and whether it is visible. It is not about whether sign-out wipes caches, and not about how deep the everyday personal-device entry sits.

Why it happens

The schema on a shared device is “finish this job,” not “manage my account.” Once the goal is done (form submitted, mail read, demo over), attention leaves the app and sign-out is not on the list. Browser “remember me” and long-lived app tokens turn a borrow into long occupancy. A conspicuous prompt binds sign-out back to the task boundary: success page, checkout complete, before close, visible idle countdown. It must out-compete nearby marketing, or it becomes banner blindness. Treating a private device as shared is harassment; the judgment should come from explicit signals (a private window, device management mode, the person chose “this is a public device,” never tapped “this is mine” here)—not merely an IP in a cafe range.

Studying it

Finish a task on a real or role-played shared terminal, comparing no prompt, an end-page prompt, and idle countdown, and see whether the next person can enter the previous account.

Independent variables: prompt placement (end page, before close, idle), whether the session is short by default, whether “this is a public device” is offered. Dependent variables: share of sessions still alive after the task, share of next people who see the previous identity’s data, rate of prompts dismissed or resented on private devices.

Lab participants told “please sign out” erase the value of the prompt. Let the task end naturally; the facilitator must not mention sign-out. Recruit shared and private separately, or the harassment cost of a loud prompt averages away.

Where it stops holding

A “please sign out” after every action on a personal primary device is a failure; enable it only when a shared signal is present. Assistive users may need longer idle; a countdown sign-out must be extendable and disableable. Forced short sessions interrupt legitimate long editing; shared mode should declare “idle for N minutes will sign you out” at entry. Demo accounts on a projector are often a dedicated demo identity; a prompt is still required, worded as “end demo” rather than “protect your privacy.” When sharing cannot be detected reliably, ask once in the close flow rather than stay silent forever.

Applying it

  • Offer “this is a public device” or detect private/guest sessions: shorter default login, sign-out beside the primary button on the success page, a visible idle countdown that signs out when it hits zero.
  • Before window close or app kill, if the session is live and shared mode is on, block and ask whether to sign out; do not block in private mode.
  • Copy should name the risk (“the next person will see your email and files”), not only “don’t forget to sign out.”
  • Verify: walk the main task in a guest profile or private window with no mention of sign-out; check whether the session still lives and whether a second person can see the previous identity. On a private device, confirm success does not always prompt sign-out. Time the idle countdown with a stopwatch and confirm it actually signs out.

Related

  • Within the group: H6.07.1 Sign-out must be findable · H6.07.2 Sign-out must clear local sensitive data
  • Adjacent: H6.06 Multi-device sessions · H6.13 Account switching and multiple accounts
  • Search terms: shared device · public computer logout · session timeout

Cards in the same group

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/handbook/H6.07.3