For IT departments
The answers to the questions IT and security teams usually ask before allowing Eureka on company computers. Applies to version 1.0.0 of the extension.
The extension
| Name | Eureka |
|---|---|
| Extension id | pmkiepihlagmefkdcaodhbgeegcngjpg |
| Store | https://chromewebstore.google.com/detail/pmkiepihlagmefkdcaodhbgeegcngjpg |
| Browsers | Chrome; Edge (installed from the Chrome Web Store) |
| Runs on | The HTML view of acts on eur-lex.europa.eu, and eureka.legal |
Allowing it in Chrome and Edge
Both browsers use the same two enterprise policies:
ExtensionInstallAllowlist: lets users install Eureka themselves when other extensions are blocked (ExtensionInstallBlocklistset to*).ExtensionInstallForcelist: installs Eureka for every user, for a rollout. The entry is the id followed by the Chrome Web Store update address.
Chrome, as a JSON policy file (on Linux, for example /etc/opt/chrome/policies/managed/eureka.json; the same names apply in Group Policy and the Google Admin console):
{
"ExtensionInstallAllowlist": ["pmkiepihlagmefkdcaodhbgeegcngjpg"],
"ExtensionInstallForcelist": ["pmkiepihlagmefkdcaodhbgeegcngjpg;https://clients2.google.com/service/update2/crx"]
}
Edge on Windows, as a registry file (use the next free number if the lists already have entries; for Chrome the key is HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome):
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Edge\ExtensionInstallAllowlist]
"1"="pmkiepihlagmefkdcaodhbgeegcngjpg"
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Edge\ExtensionInstallForcelist]
"1"="pmkiepihlagmefkdcaodhbgeegcngjpg;https://clients2.google.com/service/update2/crx"
Use only one of the two if you need only one. The extension id has not changed since earlier versions, so existing policies keep working.
Permissions
storage: keeps the user's settings and a random install id in the browser's extension storage. Chrome syncs these between the user's own browsers when browser sync is on.unlimitedStorage: lets the extension keep a local cache of the act data it has already loaded (definitions, structure, and so on), so it is not downloaded again on every visit. The cache is limited to 300 acts and cleared on every update.- Site access: the content script runs only on
eur-lex.europa.eu/legal-content/*/TXT/HTML/*(the HTML view of an act) and oneureka.legal(only to connect the extension after signing in). It does not run on any other site.
The extension asks for no other permissions: no access to tabs, history, cookies, downloads or other websites. Neither storage nor unlimitedStorage shows a permission warning, and the update to 1.0.0 adds no new warning.
Network: the extension calls the Eureka API only, over HTTPS: newapi.eureka.legal in version 1.0.0, api.eureka.legal from a later 1.0.x release (both point at the same service). Signing in uses eureka.legal. Links in the sidebar open pages on eur-lex.europa.eu.
What leaves the browser
Sent to the Eureka API:
- The address (URL) and CELEX number of each act opened in the HTML view, with its language and the extension's version.
- The random install id, generated when the extension is installed.
- Usage events within the Eureka sidebar and the act's page on EUR-Lex: which articles are viewed and for how long, scrolling, clicks on Eureka's links and cards, tabs, searches, settings.
- Once the user signs in: the e-mail address, and the acts and articles the user follows.
- Messages the user chooses to send through the feedback form.
- As with any web request, the IP address.
Never sent: the content of pages on other websites, documents or files from the computer, browsing history, or the text of the EUR-Lex page itself. The page is read in the browser to place the links; the act data shown in the sidebar is retrieved by the Eureka service from the Publications Office of the European Union, not uploaded from the user's browser.
Sign-in is by a link sent to the user's e-mail address; there are no passwords. After signing in, the extension receives its own key, which the user can revoke per browser on the account page.
Where it is processed
- Hosting: Hetzner, on servers in the EU. The Eureka API, its database and this website run there.
- Anthropic produces the AI evaluations. It receives the published text of acts; it receives no data about users.
- The e-mail provider (Porkbun) sends sign-in links and e-mail alerts. It receives the recipient's e-mail address and the message.
All connections between the browser, this website and the Eureka API are encrypted in transit (HTTPS/TLS).
Retention and deletion
In short: sign-in links and connect codes are deleted once used or expired. Page views and usage events are kept under the pseudonymous install id or user id. IP addresses are shortened after 30 days. Deleting an account removes the e-mail address, follows and notifications and unlinks the remaining history from the person and the organisation, which leaves it anonymous. The full rules are in the privacy policy.
A user can delete the account on the account page, or ask us through the contact form.
AI-generated content
Some features are AI-generated evaluations: translation notices, timeline entries, summaries of what changed between versions, and corrigenda verdicts. Each is marked "AI" in the extension. They are aids to reading, not legal advice, and they can be wrong. Definitions and articles are shown as published on EUR-Lex; the text of the act is never paraphrased. Only the Official Journal of the European Union is authentic.
Company accounts
An organisation can have one account with a number of seats. Users who sign in with an e-mail address on the organisation's verified domain join it automatically while seats remain. The organisation's administrators can invite addresses from other domains and remove members; a removed member keeps a private account. The organisation is billed per seat. Prices are on request through the contact form; see also Pricing.
Contracts and contacts
- Data processing agreement: on request, through the contact form.
- Security reports: security@eureka.legal.
- Other questions: the contact form.
See also the privacy policy, the terms and the changelog.