EtherPK has two storage modes with different backup and recovery rules. A local graph is a folder of readable files on your device. A synced graph is encrypted data on a Sync Server, with a working copy in each browser that opens it. Everything else EtherPK keeps is derived from one of those and can be rebuilt.

Local graphs

For a local graph (Local Graphs) the folder you chose is the source of truth:

<your-graph>/
  journals/   2026-06-02.md
  pages/      Quantum Mechanics.md
  assets/     diagram.a1b2c3d4.png
  etherpk/    settings.json, quick-notes.json, protection.json, theme-<id>.jsonc
  AGENTS.md, CLAUDE.md

These are ordinary files. Open them in another editor and back them up with git, Syncthing, a cloud-drive folder or your usual backup tool. A protected document's file holds only ciphertext, and etherpk/protection.json is the wrapped key that opens it - back both up together (Protected Documents). Graph Folder Layout describes every file.

EtherPK also remembers the folder in browser storage and builds a search index there. Both are disposable: if browser storage is cleared, your files remain, and opening the folder again rebuilds the index.

Synced graphs

For a synced graph (Synced Graphs) the Sync Server holds the source data as encrypted document updates, snapshots and encrypted assets. Encryption and decryption happen on your device. The server sees account and membership records plus ciphertext, and not your notes, titles, graph name, settings or images.

Each browser keeps a copy of the documents so the graph opens quickly and survives a dropped connection. That copy is readable inside the browser's storage on the device, which is what the device's own lock screen protects and what protected documents add a second layer over. Edits that have not reached the server wait in an encrypted outbox in the same storage. The copy is not a readable folder and not a backup: clearing browser data removes it, and can remove outbox work that has not reached the server yet.

Your Recovery Code unlocks your encryption keys, which the Sync Server stores sealed and cannot read. It does not contain your notes and cannot recover data deleted from every copy (Recovery Code And Device Approval).

A Local Mirror puts a readable copy of a synced graph in a folder on one of your computers, kept up to date while the graph is open there. An export is the same copy taken once, as a zip, from any browser. Either is a backup you own outright, and importing it rebuilds the graph (Keeping A Local Copy Of A Synced Graph). Both carry your protected documents as ciphertext and the wrapped key that opens them, so they stay protected by your passphrase in the copy (Protected Documents).

The demo graph

The demo is stored in the browser's private storage, like a synced graph's copy but with no server behind it. Nothing written in it is backed up anywhere - clearing site data, or a phone browser tidying up, loses it and the next visit starts afresh (Managing Your Graphs).

What the browser holds

Depending on the graph, browser storage can hold:

  • the list of graphs on this device, and a local graph's folder handle
  • the search, backlink and task index
  • a synced graph's cached documents and its outbox
  • a device-local key that keeps your synced graphs unlocked here
  • the passkeys bound to your protected documents
  • per-device settings: layout, recents, reading positions, the Tasks filter, the editor font size, lock timings, the theme.

Signing out hides synced graphs - it does not remove any of this. On a shared machine, Remove synced graphs from, on each Sync Server's tab under Sync, removes the copy, index and per-device settings of every synced graph from that server in the browser, for every account that has used it, and locks the keys held there for that server. Copies left by a server this device no longer connects to are removed under This browser, below the server tabs. The graphs stay on the sync server. It counts any changes that have not reached the server first and offers to download them. Remove from this device, on one synced graph, removes the same things for that graph.

The index can always be rebuilt and a folder can be picked again. A synced graph's documents download again from the server once your keys are unlocked. The outbox cannot be reconstructed after browser data is cleared, so check that a graph is caught up before clearing data or retiring a device: open it and wait until its sync status says Synced (Synced Graphs).

Browsers, phones especially, sometimes drop the larger part of this storage on their own to free space, while keeping the small part that holds your sync connection, your unlocked keys and your settings. EtherPK keeps a copy of the two things that would otherwise go with it, which synced graphs are set up on this device and the passkeys bound to your protected documents, in that small part, and puts them back on the next load with a notice listing what was restored. The documents then download again. This browser, on the Sync tab, says whether the browser has agreed to keep EtherPK's data, and how much it is using. Installing EtherPK as an app is the surest way to make a phone's browser agree (Installing EtherPK As An App).

At a glance

Data Local graph Synced graph Readable where
Notes and settings The folder, authoritative The server, encrypted, and a copy in each browser The folder and the browser's copy
Images and files The folder The server's storage bucket, encrypted in chunks The folder and the app
Protected documents Ciphertext in the folder Ciphertext on the server and in the browser Only in the app, unlocked
Search index Browser only, derived Browser only, derived The device
Graph list Browser only Browser plus the server's membership records The device
Local Mirror Not needed A folder you choose, one-way copy The folder
Recovery Code Not used Kept by you, outside EtherPK Wherever you keep it

What ever leaves your device

  • Local graph, no sync: none of its content. EtherPK is served from its website, and the folder is read and written by the browser on your machine.
  • Spell check downloads each language's dictionary once from dictionaries.etherpk.com (or the host your deployment sets). The request names the dictionary - none of your text is sent (Spell Check).
  • Synced graph: ciphertext, opaque ids, your account details and which graphs it belongs to, and byte counts for limits. Presence (cursors) is relayed encrypted and never stored.
  • A web image in a note (![…](https://…)) is fetched from that site each time the note is shown.
  • A published site contains exactly the documents you marked public, rendered (Publishing Your Notes As A Website).
  • An agent sees what the Headless Client serves it, on the computer it runs on, never a protected document (The Headless Client).

Backup advice

  • For a local graph, back up the folder.
  • For a synced graph, save the Recovery Code and keep a Local Mirror on a trusted device.
  • For protected documents, remember the passphrase or bind a passkey on more than one device - nothing else can open them.
  • Before clearing browser data or retiring a device, open each synced graph and wait until its sync status says Synced.
  • Forgetting a graph removes it from the device only. It does not delete a local graph's folder or a synced graph from the server.