Managed Sync
A synced graph is kept on a Sync Server. EtherPK Managed Sync is the one EtherPK runs, at sync.etherpk.com, tied to an EtherPK Account and paid for by Sync+. It stores your graphs end-to-end encrypted, so it cannot read your notes, their titles or your graphs' names.
Connect the Client
Sign in to your EtherPK Account and the Client follows. If the Client is not signed in, open the Sync tab on the Knowledge graphs page, choose Managed Sync and select Continue to secure sign in. The Client signs in with your account and connects. Your plan and usage appear on the Knowledge graphs page's Sync tab, and the header shows your email with a menu that reaches Graphs, Account, Access tokens, Sign out of EtherPK and Disconnect this device.
The three apps keep separate sessions and never share a cookie - the Client asks for a short-lived token when sync needs one and never keeps it in storage. If your session expires, the Client asks you to sign in again and keeps local edits waiting. Changing your account's email address changes nothing about your graphs: the account is identified by an immutable id, and email and name are profile details.
Sign out of EtherPK in any of the three apps signs all three out. Disconnect this device in the Client ends only this device's sync connection and locks its keys, and stops the Client signing itself back in for the rest of the browser session - choosing Managed Sync again reconnects. Plans, billing and what happens when a subscription ends are in Your EtherPK Account.
A custom server
Add a Sync Server on the Sync tab also offers Custom server, for a Sync Server other than EtherPK's that you have been given the address of. It is added beside Managed Sync, not in place of it (Synced Graphs). The Client connects to it with that address and a Personal Access Token - the server's Access tokens page shows the one and creates the other. The token proves your account on every sync request and cannot decrypt anything. Forget this server on its tab forgets the address and token on this device - revoking the token on the server removes its access completely. Resetting your password on that server revokes every token the account holds, so each device connected with one needs a new token. A graph belongs to the server it was created on.