What it means
Lock keeps encrypted vault data on the device and permits an offline unlock using an allowed local method. Log out removes local vault data and requires a fresh online authentication, including the configured second step. Both are responses to a timeout, but the selected duration is a separate setting from the action. Bitwarden clients can each have their own values.
A real-world example
A traveler locks a laptop extension before boarding a flight and can unlock it offline. On a shared library computer, logging out removes the local vault copy when the session ends.
What to do
Set the timeout action according to device ownership, test the actual client after the chosen trigger and keep your master-password and second-factor recovery methods available elsewhere.
The distinction that matters
Lock does not erase a stolen device's data and Log out does not retract passwords someone saw before logout. Browser tab closure and desktop app closure can behave differently. A strong operating-system lock remains necessary; a vault timeout alone is not a complete lost-device plan. Check whether biometric or PIN unlock is allowed on that client, because convenient local unlock changes who can reopen it. If you switch to Log out, first confirm that you can still reach the second-factor method; otherwise the safer-looking choice can lock you out during travel.
Bitwarden timeout-action details