Session Locking and Sign-Out
How PopaDex session locks, timeouts and sign-out work, including browser-storage limits.
PopaDex can lock access to encrypted values or ask you to sign in again when a session expires. Use your device’s screen lock when stepping away; application timeouts are an additional control.
When does a session expire?
The current web implementation has several timeout paths:
| Control | Configured period |
|---|---|
| Server encryption-session timeout | 15 minutes since the tracked encryption-session activity. |
| Browser crypto-session idle timeout | 30 minutes since tracked key use. |
| Browser inactivity sign-out check | 30 minutes since tracked user interaction, subject to its password-cache checks. |
| UI timeout monitor | Uses server-provided information when available, with a 15-minute fallback. |
These timers track different activity and are checked through browser events, periodic checks or server requests. They do not guarantee that every screen locks at exactly the same elapsed time. Browser suspension and background-tab behavior can affect when checks run.
What locking does
Locking releases the crypto-session manager’s active encryption-key reference and signals other components to lock. It keeps the wrapped, encrypted key in browser IndexedDB so it can be unlocked again.
A lock does not delete your saved financial records. It also does not guarantee that every previously displayed value has been erased from the screen or memory, or that every password cache has been cleared.
Unlocking or signing in again
Follow the prompt shown in the app. Depending on the session state, you may be asked to unlock encryption or sign in again. Native keychain-backed flows can differ from the web password flow.
If you have forgotten your password, read password reset and recovery first. Restoring sign-in and restoring access to encrypted financial values are separate operations.
Signing out
Sign-out ends the account session and attempts to clear encryption-session state and local key storage. It is a stronger action than releasing the active key reference, but it does not erase downloaded files, browser history, screenshots or every possible cached copy.
The current web app temporarily stores readable password values in browser storage. Cleanup differs across paths, so a locked screen or closed tab is not proof that all sensitive local state has been removed. See the implementation details.
On a shared device, sign out when finished and close your browser session. Use the device’s own screen lock for an immediate lock; this guide does not prescribe a PopaDex keyboard shortcut or promise biometric unlocking on every platform.