Signing in on a Mac you share with someone else
A Mac in a kitchen, a Mac at a reception desk, a Mac in a small studio where three people take turns. One login, several people, and a messaging account that has to be signed in for any of it to be useful. The question is rarely whether the service works. It is what the next person sees when they sit down.
The honest answer is that a browser session left signed in is a signed in session for whoever is at the keyboard, and no amount of closing tabs changes that. There are four layers of separation available on a Mac, they cost different amounts of effort, and picking the wrong one is why people end up reading someone else's messages by accident.
Start with the layer almost nobody uses
macOS has account separation built in, and it is the only layer that separates everything at once.
Apple describes four kinds of user account. An administrator can add and manage other users, install applications, and change settings. A standard user can install applications and change their own settings, but cannot add other users or change other users' settings. A sharing-only user can reach shared files remotely but cannot log in to the computer. A guest account exists for occasional users, and it has no access to other users' files or settings.
Each account gets its own home folder, its own browser profiles, its own keychain, its own notification settings, and its own Dock. Nothing is shared unless it is deliberately placed in a shared folder. Apple's own summary is that each person can personalize settings and options without affecting other users.
Adding a standard account for the second person solves the entire problem in about four minutes, and fast user switching in the menu bar makes swapping between them quick enough that nobody has to close their work first. For a household Mac, this is almost always the right answer, and the reason it gets skipped is that setting it up requires a moment of friction at the exact point where someone just wants to check a message.
The path runs through System Settings, then Users and Groups, then Add User, choosing Standard rather than Administrator unless the second person genuinely needs to install software. Turning on fast user switching, in System Settings under Control Center, puts a menu bar item that swaps accounts without logging anything out, so a long running download or an open document in the first account survives the switch. The cost is memory, since both sessions stay resident, which on a Mac with plenty of it is not worth thinking about and on an older machine with eight gigabytes is worth noticing.
Worth knowing before committing: a standard account cannot see into another account's home folder, but an administrator account can. Two administrators on one Mac are not separated from each other in any meaningful sense, so the second account should be standard if the separation is supposed to mean something.
When a second account is not on the table
Several situations rule it out. A managed work machine may not allow creating accounts. A machine that runs something continuously, a display, a till, a studio recorder, cannot be logged out and back in casually. And sometimes the sharing is not planned at all, because the Mac was only ever going to be borrowed for a minute.
In those cases separation has to happen inside the single login, which means browser profiles, separate apps, or the service's own locks. Each one covers less ground than a macOS account does, and knowing what each one misses is the whole point.
What actually leaks inside one login
It helps to be specific about what is exposed, because the answer is broader than the open tab.
The session cookie is the obvious one. A signed in service stays signed in until it is signed out, and reopening the browser restores it. Next to it sits saved autofill data, browsing history, and anything saved to the Downloads folder, which is shared across every application in that login.
Then there are notifications. A message that arrives while somebody else is using the Mac raises a banner with a sender name and usually a preview of the text. That banner appears regardless of which application is in front, and it is the most common way private content reaches the wrong person on a shared machine.
Finally there is the browser's own memory of who was there. Chrome profiles signed into a Google account pull down bookmarks, saved passwords, and extension settings. A second person using that profile inherits all of it.
| Layer | Separates sessions | Separates notifications | Separates files | Effort |
|---|---|---|---|---|
| Second macOS account | Yes | Yes | Yes | Four minutes, once |
| Separate browser profiles | Yes | Partly | No | Two minutes, once |
| Standalone app per person | Yes | Yes | No | Two minutes, once |
| Private browsing window | Yes, until closed | No | No | None |
| The service's own lock | No | Yes, while locked | No | Two minutes, once |
The controls the service itself provides
WhatsApp publishes several controls that apply directly to a shared machine, and they are more useful than most people realise.
The first appears before signing in at all. When the web version is opened, the option to stay logged in on this browser can be unchecked before the code is scanned, and the session is then logged out automatically when the tab or browser is closed. For a Mac that is borrowed occasionally, this single checkbox removes the persistent session problem entirely.
The second is app lock. Under Settings, then Privacy, then App lock, a password of between six and one hundred twenty eight characters can be set, and the client can be told to lock after one minute, fifteen minutes, one hour, or eight hours. Locking can also be triggered manually, with Cmd Ctrl L on a Mac. The documentation notes the part that matters most here: notifications do not appear while the app is locked.
The third is an audit. The list of linked devices lives on the phone, under Linked devices, and each entry can be selected and logged out individually. All active web sessions can also be logged out from the phone at once. WhatsApp recommends checking this list regularly, and adds a caution worth repeating: it cannot provide information about who accessed an account, or when, or from where. The list shows that a device is linked, not who was using it.
The fourth is two-step verification, which protects the account from being registered elsewhere rather than protecting the screen in front of you. It is worth turning on regardless, but it does not address a session left open on a shared desk.
Notifications are the part that gets forgotten
Locking a session does nothing about the banner that already appeared. On a shared Mac, notification behaviour deserves an explicit decision rather than whatever the default happened to be.
macOS handles this in System Settings under Notifications, per application. Previews can be set to show always, only when unlocked, or never. Setting previews to never means a banner still announces that a message arrived, without revealing the sender or the content, which is usually the right compromise on a machine other people can see.
The same setting exists per application, which is exactly why the next section matters. A service running inside a browser tab inherits the browser's notification settings, so turning off previews for one service turns them off for every site in that browser. A service running as its own application has its own entry in the Notifications list, and can be configured independently of everything else.
One icon per person, rather than one browser for everyone
The arrangement that works best inside a single login is to stop treating the browser as the container.
Browsers offer part of this already. Chrome supports multiple profiles with separate cookies and separate saved passwords, and a page can be installed as an app from the More menu, under Cast, save, and share. Safari can add a page to the Dock from the File menu or the Share button, and Apple describes the result as a web app that runs independently of Safari and shares no browsing history, cookies, website data, or settings with it, saved into the Applications folder of the home folder.
The gap is that a browser installed app belongs to the profile it was created from. Two people sharing one login and one browser profile end up with two icons pointing at the same session, which looks like separation and is not. Safari's web apps have no profile separation and no extension support at all.
A tool that turns a website into a standalone Mac app closes that gap by giving every generated app its own isolated cookies, session, and cache, independent of the browser profile. Two chat apps can therefore sit in the Dock of a single macOS login, each signed in to a different account, neither able to see the other's session, each with its own entry in the macOS notification settings so previews can be turned off for one and left on for the other. The Features page describes how per app profile isolation works, and the FAQ covers what happens to the stored profile data when a generated app is deleted, which is the question that matters when someone leaves the household or the office.
This is separation inside one login, not separation of the login itself. Anyone with administrator access to that Mac can still reach the files. For a family Mac or a small studio that is usually acceptable. For a machine shared with people outside that circle, the second macOS account is still the correct answer.
Choosing by who the other person is
The right layer depends less on technology than on the relationship.
For a Mac shared with a partner or a housemate, where the concern is accidental exposure rather than deliberate snooping, separate apps with isolated profiles and previews turned off will cover nearly everything, at almost no daily cost.
For a Mac shared with colleagues, or one that sits where customers can see it, use separate macOS accounts and treat the browser as disposable. Uncheck the option to stay logged in, and check the linked devices list on the phone weekly.
For a Mac borrowed once, use a private browsing window, uncheck the option to stay logged in before scanning, and log the session out from the phone afterwards. The one thing not to do is sign in normally and trust that closing the tab was enough.
What to change first
Open the linked devices list on the phone and log out anything unrecognised, because that takes thirty seconds and is the only step that undoes past mistakes. Then decide which layer the situation actually calls for: a second macOS account if the Mac is shared with people outside the household, or isolated per app sessions if it is shared inside one. If it is the second, give each account its own icon with a site to app tool such as Kagemusha and set notification previews per app rather than per browser.
Frequently asked questions
Does closing the browser sign me out?
Only if the session was set up that way. When the web version is opened, the option to stay logged in on this browser can be unchecked before the code is scanned, and the session then logs out when the tab or browser is closed. Left checked, the session survives closing the browser and restarting the Mac.
Can I lock the chat window without signing out?
Yes. Under Settings, then Privacy, then App lock, a password of six to one hundred twenty eight characters can be set, with automatic locking after one minute, fifteen minutes, one hour, or eight hours. Cmd Ctrl L locks it immediately on a Mac, and notifications do not appear while the app is locked.
How do I find out whether someone else used my session?
The linked devices list on the phone shows every device currently linked, and each can be logged out individually. WhatsApp states that it cannot provide information about who accessed an account, or the time and location it was accessed, so the list confirms that a device is connected rather than who was at it.
Do separate browser profiles keep two people apart?
They separate cookies, saved passwords, and history, which covers the session itself. They do not separate the Downloads folder, the keychain, or macOS notification settings, all of which belong to the login rather than the profile. Full separation requires separate macOS user accounts.
Is a guest account enough for someone borrowing the Mac?
For the borrower's own privacy, yes, since a guest account has no access to other users' files or settings and its data is removed at logout. It does not protect a session already signed in under the main account, because that session lives in a different login and is untouched by the guest using the machine.