Kora

Updated October 7, 2026

Privacy

This page explains data handling for Kora at koraspace.online and its Windows app. Contact the project at contact@koraspace.online or through the contact form.

Accounts and workspace data

Kora uses Supabase for account authentication and hosted workspace data. Your account information, boards, tasks, uploaded task images, membership information and completed focus-session history are used to provide the workspace. Shared workspace content is accessible to members according to their access permissions.

Data on your device

Kora uses browser or app storage for session state, preferences, cached data and local focus settings. Local demo mode stores workspace data on the device. Clearing browser or app data can remove local information.

Contact messages

The contact form sends your name, reply email, subject and message to a private Supabase table and sends an email notification through Resend. These details are used to respond to your message. Cloudflare Turnstile checks submissions for abuse; a hashed client-IP identifier is used for rate limiting. Do not send passwords or sensitive information through the form.

Music and optional analysis

The Music Companion reads supported tabs' track metadata and playback state for music controls and Beat Grid. Supported local audio capture analyzes browser audio; on Windows, other audio from the same browser, including calls, may affect the result. Read the Music Companion privacy details before enabling it.

Server Beat analysis uses an authorized media input and stores reusable, timestamped music events rather than workspace content. This capability is still in development and is not available for every media source.

If you request AI task breakdown, the task details needed for that request are sent to the configured AI service. Avoid including confidential information in such requests.

Service providers and retention

Netlify hosts the web app; Supabase provides authentication and data services. Email, anti-abuse and optional analysis providers process the information needed for their functions. Hosting and service providers may process network requests and operational logs.

Hosted workspace data and contact messages are retained to operate the product and respond to users. Backups and operational logs may remain after live data is removed. Contact Kora to request access to or deletion of your account data; identity and workspace permissions may need to be verified.

Changes

As this Early Access product develops, this page will be updated when data handling changes. Check the date above for the latest revision.