← Music setup

Music Companion privacy

The extension connects supported browser music to Kora Floating Focus for playback controls and beat lighting.

What it reads

While Floating Focus is open, it reads title, artist, playback position/state and site name from supported YouTube, YouTube Music, SoundCloud, Spotify Web, Apple Music, Deezer and Tidal tabs. Access uses an explicit host list, not all websites. Localhost access supports development. It does not read account passwords, messages or browsing history.

Optional live beat sync

Clicking Kora Music Companion while viewing your selected music tab can grant browser access for local beat analysis. Capture is attempted automatically while Floating Focus is open and music is playing; only the browser can grant access. The browser shows a capture indicator, and the dock displays a listening message. The capture recipe initially requests audio and video; video tracks are stopped immediately and are never analyzed, displayed or recorded. Audio is analyzed locally and passed to your speakers so playback continues. No microphone access is requested.

Where data goes

Metadata, detected band onsets and scalar instrumental-note/tempo signals go to the Kora app tab at koraspace.online, kanthangboard.netlify.app or approved local development origins, or to the running Windows widget through a loopback-only WebSocket at 127.0.0.1:47635. Kora 0.1.15 captures the process tree of the browser owning that connection automatically on Windows, using a bounded local IPC Channel for PCM. Other audio in that same browser, including calls, can affect beats; the source picker does not isolate tab audio. Other desktop processes are excluded. Browser sound and volume remain unchanged. Audio and video are never saved to disk or uploaded. There is no tracking service, listening history, music login or API key.

Cached Beat events

Kora requests precomputed Beat events from its hosted API using the active music provider and public media identifier. The hosting service receives ordinary request information, including your IP address. If server analysis is configured, a cache-miss request uses your Kora sign-in token to authenticate that request. Audio is not uploaded. While cached events are unavailable, local analysis or an explicitly labelled decorative fallback continues.

Optional AI instrument notes

Choose AI instrument notes in Kora’s music controls to open the companion’s setup page. Enabling it downloads about 157 MB of Spleeter model weights from Hugging Face; the download host receives ordinary request information such as your IP address, but no song metadata or audio. Executable code and WebAssembly are bundled in the extension. Verified model weights stay in this browser profile’s Cache Storage, and local storage remembers your enable/disable preference and latest setup error. No account or API key is required.

During enabled capture, a bounded audio buffer remains only in volatile memory. Original audio is delayed 3.5 seconds so all five rows can follow the same audible timeline. Music videos consequently have delayed sound. Pause, seek, source switch and stopping capture discard buffered audio and pending notes. The model separates vocals, drums and bass before tracking a dominant instrumental line; it cannot guarantee every note or eliminate all leakage. If analysis fails, the fifth row stays dark. Turning it off restores immediate audio; remove the extension to remove its model cache and preferences.

In native Kora, the AI button enables a separate local model cache in the app, with executable code/WASM included in the installer. AI instrument flashes follow with processing delay; sound and percussion rows stay immediate. Pause, seek and source changes clear pending flashes. Disable AI to leave row five dark. The 3.5-second audio delay described above applies to web/PiP tab capture only.

Protected playback

All explicitly supported services attempt normal browser-approved tab capture, including when their media elements use encrypted playback. A platform name or encrypted-media flag does not establish that tab audio is unavailable. Live mode is reported only after the analyser receives audible audio. Silent or denied capture falls back to clock mode without simulating beats; metadata and ordinary play/pause remain available. No media is decrypted or recorded, and this extension does not bypass DRM or browser capture restrictions.

Permissions

Site access and scripting read media state and invoke play/pause. On supported music sites, a page-context observer tracks standard HTML audio/video playback, including audio objects outside the document; the music clock script relays their playback state. The app relay runs on Kora. Kora site access also locates an existing app tab so the toolbar click can return you there without opening duplicates. activeTab and tabCapture support capture after extension invocation. An offscreen USER_MEDIA document hosts the temporary local audio analysis.

Temporary preferences

Browser-session storage remembers only the last approved Kora origin and tab ID, the music tab you clicked, and a random selection token. These help return you to the app and select your song. They are not listening history, contain no audio or song titles, and are cleared when the browser session ends or the extension is reloaded, updated or disabled.

Your control

Pause the song, close its tab, or close Floating Focus to stop capture. A short lease also releases capture if the app disappears unexpectedly. Failed capture keeps playback controls but leaves the squares gray and still. If permission is needed, a visible button opens the music tab for you to invoke the companion. Disable or remove the extension at any time. It does not control native desktop music apps or other browser profiles.

Native widget connection

The companion reconnects locally using bounded keepalives and the alarms permission. Closing the dock stops its capture subscription. The widget accepts extension origins with per-connection nonces and rejects web-page origins; this does not authenticate an extension publisher, so installed browser extensions remain a local trust boundary. No listener is exposed to your LAN.

Updated October 6, 2026.