Yes. It's for one year. Is it the recommended time..?
I don't think most websites used that.
Google: private, s-maxage=0, max-age=0, must-revalidate
Facebook: private, no-cache, no-store, must-revalidate
Twitter: no-cache, no-store, must-revalidate, pre-check=0, post-check=0
Reddit: private...