Well the refresh token doesn’t keep someone logged in per say in the sense of like logging into Facebook. It just allows you to log in once, and use the refresh_token to generate new access_tokens used for auth’d endpoints when/as they expire.
I can’t speak for how jEveAssets does it specifically, you would have to ask @Golden_Gnu.