eula

HEUREKA LABS, INC. END USER LICENSE AGREEMENT Effective Date: March 4, 2026

PLEASE READ THIS END USER LICENSE AGREEMENT (“EULA” OR “AGREEMENT”) CAREFULLY BEFORE DOWNLOADING, INSTALLING, OR USING THE HEUREKA LABS DESKTOP APPLICATION (THE “SOFTWARE”). BY CLICKING “I AGREE,” INSTALLING, OR USING THE SOFTWARE, YOU AGREE TO BE BOUND BY THE TERMS OF THIS AGREEMENT. IF YOU DO NOT AGREE, DO NOT INSTALL OR USE THE SOFTWARE.

  1. PARTIES AND DEFINITIONS 1.1 This EULA is entered into between Heureka Labs, Inc., a Delaware corporation with its principal place of business at 1030 N Rogers Ln, Ste 121 PMB 2165, Raleigh, NC 27610, USA (“Heureka Labs,” “Licensor,” “Company,” “we,” “us,” or “our”) and you, the individual user (“Licensee” or “User”). 1.2 “Software” means the Heureka Labs desktop application, all associated modules, updates, upgrades, patches, bug fixes, documentation, and any offline components provided by Licensor. 1.3 “Platform” means the Software together with the web-based interface, backend services, artificial intelligence and machine learning models, agents, tools, application programming interfaces, infrastructure, cloud storage, and all related services operated by Heureka Labs. 1.4 “Account” means the registered account created by or for a User or Organization to access the Platform. This includes, but is not limited to accounts used for credits, trials, pilots, projects, Software and/or Platform access, collaborations, or partnerships. 1.5 “Organization” means any entity, including, but not limited to, any university, research institute, commercial entity, laboratory, or other institution that creates or administers an account on behalf of one or more Users. 1.6 “Credits” means the prepaid usage tokens purchased and used to access and operate features of the Platform, either by individual Users or by Organizations. 1.7 “User Data” means files, data, research materials, text, images, code, or other content uploaded, created, or generated by a User through the Platform. 1.8 “Output” means any result, analysis, report, generated text, code, visualization, or other content produced by the Platform in response to or based on a User’s inputs, instructions, or data. 1.9 “Company Property” means all templates, programs, methodologies, processes, technologies, tools, agents, inventions, discoveries, techniques, materials, information, algorithms, infrastructure, and intellectual property owned, developed by, or licensed to Heureka Labs prior to or apart from any User engagement, including all associated intellectual property rights, regardless of whether such property is used in providing Platform services. 1.10 “Authorized Participants” means any third-party collaborators, researchers, associated laboratories, or affiliated institutions engaged by an Organization to participate in projects or access Services under a separate project agreement with Heureka Labs.

  2. LICENSE GRANT 2.1 Subject to the terms and conditions of this EULA and the Terms of Service, Licensor hereby grants User a limited, non-exclusive, non-transferable, non-sublicensable, revocable license to install and use the Software solely on devices owned or controlled by the User for the User’s internal research, scientific, and authorized professional purposes and in accordance with this Agreement. 2.2 This license is conditioned upon User maintaining a valid Account in good standing with sufficient Credits, as required by Licensor, and full compliance with this EULA and the Terms of Service. All terms of this EULA and the Terms of Service apply equally to all Account types, including Accounts for credits, trials, pilots, projects, Software and/or Platform access, collaboration, or partnerships. 2.3 This EULA governs the desktop Software specifically. Use of the web-based interface and all backend Platform services is additionally governed by the Terms of Service. In the event of conflict between this EULA and the Terms of Service, the Terms of Service shall control with respect to Platform services and the EULA shall control with respect to the Software license. 2.4 From time to time, Heureka Labs may make the Software or Platform features available in connection with Promotional Programs as described in Section 3.8 of the Terms of Service. Access to the Software or Platform features pursuant to a Promotional Program is subject to the applicable Promotional Terms in addition to this EULA.

  3. RESTRICTIONS 3.1 User shall NOT, and shall not permit any third party to: • Copy, reproduce, duplicate, or distribute the Software except as expressly permitted in this EULA; • Modify, adapt, translate, reverse engineer, decompile, disassemble, or attempt to derive the source code, underlying algorithms, model weights, system prompts, or architecture of the Software or any component of the Platform; • Create derivative works based on the Software or any Platform component; • Sell, resell, rent, lease, sublicense, assign, or otherwise transfer the Software or any rights hereunder; • Remove, alter, or obscure any proprietary notices, trademarks, or labels on or in the Software; • Use the Software for any purpose other than User’s own authorized research and scientific activities; • Use the Software to develop a competing product or service; • Scrape, screenshot, or record Platform interfaces, agent behaviors, system prompts, or model outputs for the purpose of competitive intelligence, model replication, or circumventing the restrictions of this Agreement; • Circumvent or attempt to circumvent any technical protection measures, authentication systems, encryptions, or security controls of the Software or Platform; • Inject malicious code, conduct penetration testing without prior written authorization, attempt to access unauthorized areas of the Platform infrastructure, or engage in any activity designed to compromise the security or integrity of the Software or Platform; • Use the Software to conduct weapons research, human cloning research, dual-use pathogen research, or any research that is illegal under applicable law; • Engage in prompt injection attacks, model extraction, or any attempt to replicate, circumvent, or reverse-engineer the proprietary AI models, agents, tools, features, capabilities, or infrastructure underlying the Platform; • Use the Software to generate spam, phishing content, or unsolicited mass communications; use the Software to attempt to access, harvest, or reconstruct data belonging to other Platform users; or engage in any of the prohibited AI misuse activities described in Section 6.7 of the Terms of Service; • Use the Software or Platform in violation of any applicable export control or sanctions laws. 3.2 Confidentiality Obligations. (a) Definition. ‘Heureka Labs Confidential Information’ means non-public technical information specifically identified or reasonably understood to be confidential at the time of disclosure, including: (i) proprietary details of Heureka Labs’s internal platform architecture, AI models, algorithms, tools, agents, infrastructure, software, processes, methodologies, source code, model weights, data, and algorithmic design, to the extent such details are not discernible from ordinary use of the Platform; (ii) non-public business, financial, or strategic information of Heureka Labs; and (iii) information designated in writing as ‘Confidential’ by Heureka Labs. For the avoidance of doubt, Heureka Labs Confidential Information does NOT include: (A) the general capabilities, features, and functionalities of the Platform as experienced through ordinary use; (B) the content, nature, or characteristics of Outputs generated by User; (C) the existence of User’s engagement with Heureka Labs; or (D) information that User is required to disclose pursuant to Section 6.5 of the Terms of Service (publication disclosure obligations). (b) Obligations. User shall: (i) maintain Heureka Labs Confidential Information in strict confidence using at least the same care used to protect User’s own confidential information, but no less than reasonable care; (ii) not disclose Heureka Labs Confidential Information to third parties without Heureka Labs’s prior written consent; (iii) use Heureka Labs Confidential Information solely for User’s authorized use of the Platform; and (iv) not reverse engineer, decompile, or disassemble any component of the Platform to derive non-public technical information. (c) Duration. These obligations apply during the term of User’s Account and for five (5) years following termination or expiration. (d) Exclusions. These obligations do not apply to information that: (i) was rightfully known to User prior to disclosure and free of any obligation of confidentiality; (ii) becomes publicly available through no act or omission of User; (iii) is independently developed by User without reference to or use of Heureka Labs Confidential Information; (iv) is received by User from a third party lawfully entitled to disclose it without restriction; or (v) User is required to disclose pursuant to applicable law, regulation, valid legal process (including subpoena, court order, or regulatory demand), or the order of a court or governmental authority of competent jurisdiction (“Legally Compelled Disclosure”), provided that: (A) User provides Heureka Labs with prompt written notice of such requirement as soon as practicable and in advance of disclosure to the extent permitted by applicable law, to allow Heureka Labs to seek a protective order or other appropriate relief; (B) User discloses only that portion of the Heureka Labs Confidential Information that is legally required to be disclosed; and (C) User uses commercially reasonable efforts to obtain confidential treatment of the disclosed information from the receiving authority.

  4. INTELLECTUAL PROPERTY OWNERSHIP 4.1 Licensor Ownership. The Software and all components of the Platform, including but not limited to the application code, user interface design, templates, AI models, agents, tools, features, capabilities, infrastructure, APIs, proprietary methodologies, algorithms, and all intellectual property embodied therein, constitute Company Property and are and shall remain the sole and exclusive property of Heureka Labs and its licensors. All rights not expressly granted herein are reserved. 4.2 Company Improvements. (a) Ownership. Heureka Labs continuously develops and improves its platform technologies through its own independent research and engineering, including but not limited to improvements to application code, user interface design, templates, AI models, agents, tools, features, capabilities, infrastructure, APIs, methodologies, algorithms, machine learning models, methodologies, and all intellectual property embodied therein (“Company Improvements”). All Company Improvements are and shall remain the sole and exclusive property of Heureka Labs, regardless of when they were developed or whether they were developed during a period when any User was active on the Platform. (b) User Waiver. User hereby irrevocably waives and releases any claim to ownership of, or interest in, any Company Improvement, including any claim based on: (i) User’s interaction with the Platform during any period of development; (ii) similarity between a Company Improvement and any Output previously generated by User; or (iii) any theory of joint development, unjust enrichment, or implied license arising from User’s Platform use. This waiver applies to all Company Improvements, whether developed before, during, or after User’s engagement with the Platform to the maximum extent permitted by applicable law. (c) No Admission. Nothing in this Section constitutes an admission or representation by Heureka Labs that any Company Improvement was or was not influenced by User interactions. Heureka Labs makes no representations regarding the technical processes by which Company Improvements are developed, except as expressly set forth in Section 4.5 (License to Heureka Labs) and Section 4.3 of the Terms of Service (No AI Training on User Data). 4.3 Trademarks, Branding, and Reference Rights. (a) Heureka Labs Marks. The Heureka Labs name, logo, product names, service marks, and all associated branding are the exclusive property of Heureka Labs. Users may not use any such marks without Heureka Labs’s prior written consent, except that Users and their Organizations may identify Heureka Labs as the platform used in disclosures made pursuant to Section 6.5 of the Terms of Service (Platform Use Disclosure), citations in publications, grant applications, and equivalent scholarly materials, in each case in a manner consistent with Heureka Labs’s published citation guidance. (b) License to Use User and Organizational Marks. Subject to this Section 4.3, each User and, where applicable, their affiliated Organization (“Mark Holder”) hereby grants Heureka Labs a non-exclusive, worldwide, royalty-free license (the “Reference License”) to: (i) display and reproduce the Mark Holder’s name, logo, and institutional branding (“Marks”) in Heureka Labs’s website, pitch decks, investor presentations, marketing collateral, press materials, conference presentations, case studies, social media, and other promotional or communications materials; (ii) identify the Mark Holder by name (with or without logo) as a customer, user, partner, pilot participant, or research collaborator of Heureka Labs in any oral, written, or digital communication; (iii) describe, in general terms, the nature of the Mark Holder’s use of the Platform (e.g., “conducts AI-assisted drug discovery research using Heureka Labs”) without disclosing confidential details of User Data, Outputs, or research findings; and (iv) include the Mark Holder’s name and/or logo in aggregated lists of Heureka Labs customers, partners, or research collaborators. (c) Permitted Use Standards. Heureka Labs shall use Marks only in a form and manner that: (i) does not materially alter or distort the Mark Holder’s branding; (ii) does not state or imply that the Mark Holder endorses any specific product, feature, claim, or representation of Heureka Labs beyond the fact of use; (iii) does not associate the Mark Holder with content that could reasonably cause material reputational harm to the Mark Holder; and (iv) complies with any written brand usage guidelines provided by Mark Holder to Heureka Labs at the time of opt-out or at Account creation. (d) Opt-Out. Any User or Organization may withdraw the Reference License at any time, for any reason, by providing written notice to Heureka Labs at support@heurekalabs.co with the subject line “Trademark License Opt-Out.” Upon receipt of a valid opt-out notice: (i) Heureka Labs will cease use of the relevant Marks in new materials within thirty (30) days; (ii) Heureka Labs will use commercially reasonable efforts to remove or replace existing uses of the Marks in digital materials (e.g., website, downloadable collateral) within sixty (60) days; and (iii) Heureka Labs is not required to recall, modify, or destroy printed materials, recorded presentations, or archived press placements that incorporated the Marks prior to the opt-out effective date. The opt-out does not affect Heureka Labs’s right to refer to the Mark Holder in: (A) factual, historical descriptions of past partnerships or engagements (e.g., “previously worked with [Institution]”); or (B) materials that User has individually approved in writing. (e) Authority Warranty. Each User accepting these terms on behalf of an Organization represents and warrants that: (i) they have actual authority to grant the Reference License with respect to their Organization’s Marks; (ii) the Organization’s Marks do not infringe any third party’s intellectual property rights; and (iii) neither Heureka Labs’s use of the Marks in accordance with this Section nor the grant of the Reference License will violate any agreement between the User or Organization and any third party. Users who cannot make these representations should exercise the opt-out right in Section 4.3(d) promptly. (f) Research References. Independently of the Reference License, Heureka Labs may, without restriction and without constituting a trademark use, refer to research published, presented, or deposited in a public repository by a User or Organization as having been conducted using the Heureka Labs Platform, where such reference is factual, accurately identifies the published or publicly available research, and does not disclose non-public User Data or Outputs. This right is not subject to the opt-out in Section 4.3(d) because it relates solely to factual descriptions of publicly available research and does not constitute trademark use. (g) No Endorsement Implication. Nothing in this Section constitutes Heureka Labs’s endorsement of any User’s or Organization’s research, conclusions, products, services, or business practices. Heureka Labs may include a disclaimer of endorsement in materials where appropriate. 4.4 User Data and Outputs. As between User and Heureka Labs, User retains ownership of User Data and all Outputs that are the direct product of User’s proprietary input data, subject to the license granted to Heureka Labs in Section 4.5 and in accordance with legal limitations. Nothing herein shall be construed as granting User any rights in or to the underlying Company Property. The fact that a User has generated a particular Output does not establish any claim against any other user, researcher, or party who independently develops a similar result. 4.5 License to Heureka Labs. User grants Heureka Labs a non-exclusive, worldwide, royalty-free, sublicensable license to access, cache, store, copy, process, analyze, transmit, display, and otherwise use User Data and Outputs to the extent necessary to provide, maintain, support, improve, and operate the Platform and associated services for User. This license does not extend to use of User Data or Outputs for training Heureka Labs’s AI models, except: (a) pursuant to an explicitly executed Statement of Work or written agreement for custom model development; (b) where the User or User’s Organization has independently published such data or Outputs in a peer-reviewed journal, public preprint repository, public dataset repository, or equivalent public venue, in which case Heureka Labs may use the published version of such data for model training to the same extent as any other member of the public; or (c) where the User has the Response Ratings feature enabled as described in Section 5.11, in which case Heureka Labs may use the specific Output that the User rated, together with the associated Rating signal, solely to train or improve Heureka Labs’s AI models for the limited purpose of improving response quality and relevance. This exception applies only to Outputs individually rated by User through the Response Ratings feature and does not extend to unrated Outputs, unrated User Data, or any Output not directly associated with a submitted Rating. 4.6 User Warranty of Rights. User represents, warrants, and covenants to Heureka Labs that: (a) it has all necessary rights, licenses, consents, and permissions in and to all User Data uploaded to the Platform to grant the license in Section 4.5; (b) such User Data and its use as contemplated hereunder does not and will not infringe, misappropriate, or violate any third party’s intellectual property rights, privacy rights, confidentiality obligations, or other rights; (c) all User Data has been collected, processed, and is being shared in compliance with applicable privacy laws, data protection regulations, research ethics requirements, and institutional policies; and (d) User has obtained or will obtain all necessary consents, permissions, and approvals from data subjects, institutional review boards, regulatory authorities, and any other applicable parties to permit Heureka Labs’s processing of User Data as contemplated herein. These representations and warranties are continuing obligations throughout the term of this Agreement. 4.7 No Incorporation of Company Property. User agrees that it will not incorporate or use Company Property, Company Improvements, or Heureka Labs Confidential Information in any User deliverable, publication, or downstream work except as specifically approved in writing by Heureka Labs. 4.8 Feedback. User’s assignment and license of Feedback to Heureka Labs is governed by Section 5.6 of the Terms of Service, which is incorporated herein by reference.

  5. LOCAL AGENT PERMISSIONS, FEATURES, AND CODE EXECUTION The Platform includes desktop agent capabilities, features, and integrations that operate on or in connection with User’s local device and cloud infrastructure. All data collection, access, and transmission activities described in this Section are limited to what is reasonably necessary to provide, secure, and operate the Platform. By installing and using the Software, User acknowledges and consents to the following permissions, features, and data practices described in this Section including, but not limited to: 5.1 Filesystem Access. Certain Platform agents and tools may read from and write to directories on User’s local device to perform Platform functions. These include but are not limited to User-designated workspace directories, Platform application data directories, and a designated Platform subdirectory within User’s home directory. User controls which workspace directories are made available to Platform agents and is solely responsible for the contents of those directories. Heureka Labs does not access User’s local filesystem beyond what is necessary for Platform operations and does not transmit local file contents to Heureka Labs servers except as part of features explicitly initiated by User, such as cloud backup or cloud compute. 5.2 Code Execution. The Platform may execute code on User’s local device, including code generated by Platform agents. Such code execution is designed to limit unintended effects on the User’s broader system. Additionally, Heureka Labs shall use commercially reasonable efforts to present User with confirmation prompts before Platform agents modify, overwrite, or delete files with exceptions for (i) temporary files created and deleted within a single session, (ii) files within the Platform’s own application data directory, or (iii) operations expressly authorized by User in a prior written instruction, but User acknowledges that no mitigation mechanisms eliminate all risk of unintended system interaction, and consents to such code execution as part of Platform operations. Safety measures do not constitute a warranty or guarantee against all unintended file modifications. Heureka Labs is not responsible for the behavior of code generated by AI agents, which is subject to the disclaimers in Section 6. 5.3 Network Calls. Platform agents and services make network calls in the course of providing Platform features. These include but are not limited to calls to Heureka Labs’s own servers and infrastructure, third-party services accessed by agents during task execution, third-party plugin and integration endpoints enabled by User, and third-party service providers supporting Platform operations. Heureka Labs is not responsible for the content, availability, or data practices of third-party services. User’s use of third-party services through the Platform is subject to those services’ own terms and privacy policies. 5.4 Background Services. While the Platform is running, background services operate on User’s local device to support Platform functionality, including but not limited to workspace monitoring, context management, scheduled tasks, and notification delivery. Background services are terminated when the Platform is closed. Users may disable individual background features through Platform settings, though doing so may limit Platform functionality. Background services may consume Credits as described in Terms of Service Section 3.2. Background services operate independently of other features and may be managed through Platform settings. 5.5 Data Collection and Transmission. The Platform collects and transmits data necessary for Platform operations, including usage data, device and technical data, log data, session and memory data, response ratings data, and project and backup data associated with features User has enabled. A complete description of the data we collect and how we use it is set forth in the Privacy Policy. All data collection and transmission is governed by the Privacy Policy and, for EU/UK Users, the GDPR Data Processing Addendum. 5.6 Plugins, Skills, Extensions, Integrations, and Permissions. (a) General. The Platform supports third-party plugins, skills, agent tools, service integrations, external communication channel integrations, and hardware device integrations (collectively, “Integrations”). User acknowledges that enabling Integrations may result in data being transmitted to third-party providers. Heureka Labs does not screen or vet third-party Integrations and makes no representations regarding their safety, security, or data practices. User is responsible for evaluating any Integration before enabling it and for ensuring that its use complies with these Terms. All Integrations are subject to the Acceptable Use Policy in Terms of Service Section 6. (b) No Device Access Default. By default, the Platform does not access User’s devices. All device-level permissions are opt-in only and require affirmative User authorization at the point of activation of the relevant Integration or feature. The absence of a permission request does not indicate that no Integration is active; Users should review enabled Integrations in Platform settings at any time. User may revoke permissions at any time through Platform settings or through the User’s device or operating system permission controls. Revocation disables the relevant Integration feature but does not otherwise affect Platform access. (c) Hardware Integrations and Laboratory Equipment. By enabling a hardware Integration, User affirmatively authorizes the Platform to communicate with the designated device and represents that User has all necessary rights to connect such hardware to the Platform. Hardware Integrations may include devices like smart glasses, image capture devices, and similar hardware that may transmit image or video data to the Platform for processing, including optical character recognition, visual context extraction, and image-to-text conversion (collectively, “Visual Capture Integrations”) as further described in Section 5.14. Visual Capture Integrations are opt-in only and require affirmative User authorization at the point of activation. Heureka Labs makes no representations or warranties regarding the performance, safety, regulatory compliance, accuracy, or calibration of any third-party hardware device. User is solely responsible for proper operation and calibration of connected hardware, for verifying the accuracy of data transmitted from hardware to the Platform, and for compliance with all applicable regulatory frameworks governing such hardware, including GxP, ISO, or equivalent requirements. Heureka Labs shall not be liable for any loss or research impairment arising from reliance on data transmitted from third-party hardware devices. (d) Data Sharing with Integration Providers. By enabling an Integration that requires device permissions or Platform data access, User consents to transmission of relevant data to the third-party Integration provider to the extent necessary for the Integration’s operation, subject to that provider’s own terms and privacy policy. Such transmission is directed by User and does not constitute a disclosure by Heureka Labs for its own purposes. Heureka Labs’s no-training commitment in Section 4.5 and confidentiality obligations do not bind third-party Integration providers. 5.7 Notifications. The Platform may request permission to deliver desktop and operating system notifications for Platform events. User may manage notification permissions through their device’s system settings at any time. 5.8 Software Updates. The Software periodically checks for and may automatically download and install Updates in accordance with Section 7.1. Users may manage Update installation behavior through Platform settings as described in Section 7.1(b). Heureka Labs will provide advance notice of Updates that materially change the permissions or data practices described in this Section 5, in accordance with Section 7.1(e) and Section 13.2. 5.9 Authentication and Local Storage. (a) Authentication Credentials. The Platform stores authentication credentials using the operating system’s secure credential storage. User session data and conversation history are stored locally on User’s device using commercially reasonable security measures. Heureka Labs implements appropriate technical controls to protect authentication credentials used during Platform and agent operations. (b) Local Conversation Memory. (i) Operation. The desktop Software maintains a local conversation memory system (“Local Memory”) that stores context from prior agent interactions within User’s local account environment to enable context continuity, personalization, and improved agent performance across sessions. Local Memory is enabled by default and may be disabled by User through the Platform’s memory management interface settings. Disabling Local Memory will prevent the Platform from storing new conversational context and may reduce agent performance continuity across sessions. Heureka Labs is not responsible for any reduction in Platform functionality resulting from User’s choice to disable Local Memory. (ii) Storage Location. Local Memory data is stored in files within a designated directory on User’s local device (the “Memory Directory”). The default location of the Memory Directory will be disclosed to User within Platform settings and/or documentation. (iii) User Control — File Deletion. User may delete the contents of the Memory Directory at any time directly through User’s local filesystem. Deletion of Local Memory files will permanently erase the stored context data from User’s local device. Deleted Local Memory is not recoverable by Heureka Labs. User acknowledges that deletion of Local Memory may cause the Platform to lose conversational context, personalization data, and prior task history stored in the deleted files, and that Heureka Labs bears no responsibility for any loss of Platform functionality or research continuity resulting from User-initiated deletion of Local Memory files. (iv) No Cloud Sync (Default). By default, Local Memory files are not transmitted to or stored on Heureka Labs’s cloud servers. If User enables cloud backup or cross-device sync features, Local Memory data may be uploaded in accordance with Section 5.10. (v) Data Minimization and Retention. Local Memory accumulates data as User interacts with the Platform. Users are encouraged to periodically review and delete Local Memory files to minimize the retention of Personal Data on their local device. Platform settings may offer optional automatic deletion schedules for Local Memory files older than a User-specified period. (vi) GDPR / UK GDPR. For EU/UK Users, Local Memory constitutes processing of personal data on User’s local device. Heureka Labs processes Local Memory as a software mechanism on the basis of contract performance (providing Platform functionality). Because Local Memory is stored exclusively on User’s local device and cannot be accessed by Heureka Labs absent cloud backup, Heureka Labs acts as a software provider only with respect to the mechanisms enabling Local Memory and does not independently process the personal data stored therein. EU/UK Users may disable Local Memory at any time through Platform Settings, or delete existing Local Memory files directly through their local filesystem, as described in Section 5.9(b)(iii). Heureka Labs cannot access, retrieve, or delete Local Memory data stored locally on User’s device. 5.10 Cloud Compute. User may optionally submit computational tasks to Heureka Labs’s cloud infrastructure. By submitting a cloud task, User consents to the upload of selected files to Heureka Labs’s cloud storage for the duration of task execution. Cloud compute tasks are subject to the credit deposit and reconciliation mechanics in Terms of Service Section 3.10. Files uploaded for cloud compute will be deleted from active cloud storage within thirty (30) days of task completion, subject to standard backup processes described in Terms of Service Section 4.7. 5.11 Response Quality Feedback. (a) Feature Description. The Platform includes an optional response quality feedback feature (“Response Ratings”) that allows Users to rate individual agent responses or Outputs as helpful, unhelpful, or to provide categorical feedback regarding response quality. The Response Ratings feature is enabled by default and may be disabled by User at any time through Platform Settings. While enabled, submission of individual ratings remains voluntary. User is not required to enable or use Response Ratings as a condition of Platform access. (b) Data Collected. When User submits a Response Rating, the Platform collects: (i) the binary or categorical rating selected by User (e.g., thumbs up, thumbs down, or selected category); (ii) a session and response identifier enabling the rating to be associated with the relevant agent interaction; (iii) the timestamp of the rating; and (iv) any optional free-text comment voluntarily entered by User in connection with the rating. Response Ratings are associated with User’s Account for platform quality monitoring and improvement purposes. (c) Use of Response Ratings. Heureka Labs may use Response Ratings (including any associated free-text comments) to: (i) assess and improve the quality, accuracy, and relevance of Platform agent responses; (ii) identify systematic errors, biases, or failure modes in Platform outputs; (iii) provide training signals for Platform models and systems. For the avoidance of doubt: (A) for Users who have disabled the Response Ratings feature: no Response Ratings are collected and this Section does not apply; (B) For Users who have the Response Ratings feature enabled: binary or categorical Response Ratings (e.g., thumbs up/thumbs down, without free-text) are operational feedback signals and are not “User Data” or “Outputs” as defined in Sections 1.7 and 1.8 of this EULA. Heureka Labs may use such Rating signals, together with the specific associated Output that was rated, to train or improve Heureka Labs’s AI models for the purpose of improving response quality and relevance, as permitted by Section 4.5(c) of this EULA. By enabling the Response Ratings feature, User consents to this use of rated Outputs. This consent may be withdrawn by disabling the Response Ratings feature in Platform Settings; withdrawal is prospective only and does not affect use of Ratings and associated Outputs submitted prior to withdrawal; and (C) free-text comments submitted by User are subject to the Feedback provisions of Section 5.6 of the Terms of Service. (d) Privacy and GDPR. Collection and use of Response Ratings is described in the Privacy Policy Section 1.1 and 2. For EU/UK Users, Response Ratings constitute personal data processed on the basis of Heureka Labs’s legitimate interests in improving the Platform (GDPR Article 6(1)(f)). EU/UK Users may opt out of providing Response Ratings or object to this processing by contacting support@heurekalabs.co in accordance with Privacy Policy Section 8.5(b) and GDPR Article 21. 5.12 Local Context Packaging for Agent Inference. (a) Description. To provide contextually relevant and personalized responses from the Platform’s AI agents, the Platform may periodically package and transmit to Heureka Labs’s servers a compact, derived representation of locally stored context, which may include: (i) vector embeddings derived from note content, research documents, or other User Data processed locally; (ii) structured rationale summaries or decision logs generated by prior local agent sessions; and (iii) condensed representations of Local Memory files, session history, task context, or similar information relevant to an active or anticipated agent inference request (collectively, “Local Context Packages”). (b) Nature of Transmission. Local Context Packages are derived representations of User Data and are not transmissions of raw User Data files or documents. Transmissions occur only when necessary to fulfill an active agent inference request or to prepare the Platform for an anticipated request. (c) Server-Side Retention. Local Context Packages transmitted to Heureka Labs’s servers are retained only for the duration necessary to complete the relevant agent inference operation and are deleted from active server storage promptly upon completion, and in no event later than thirty (30) days after transmission. Local Context Packages are not used for AI model training and are not retained in a form that associates them with the User’s identity beyond the operational session in which they were transmitted, except as required for security logging. (d) Privacy. All Local Context Packages are kept in encrypted environments and are subject to the confidentiality and security measures described in Section 6 of the Privacy Policy. For EU/UK Users, transmission of Local Context Packages constitutes processing of personal data on the basis of contract performance (providing Platform functionality) and, where applicable, Heureka Labs’s legitimate interest in delivering a personalized and contextually coherent agent experience. 5.13 Messaging Channel Integrations. (a) Description. The Platform supports optional integration with external messaging channels such as email, Telegram, SMS, and mobile application integrations (collectively, “Messaging Integrations”). The integrations offered may change from time to time. Messaging Integrations allow the Platform’s agents and tools to deliver notifications, generate summaries, assign tasks, make notes, or trigger interactive agent communications through those channels. (b) Opt-In and Linking Process. Messaging Integrations are opt-in only. Users must affirmatively enable each Messaging Integration through Platform settings, which involves generating a platform-specific linking code and completing an authentication flow with the applicable third-party messaging platform. User is solely responsible for maintaining the security of their linked messaging account. (c) Data Shared with Messaging Platforms. By enabling a Messaging Integration, User consents to the transmission of certain Platform-generated content including agent-generated messages, notifications, summaries, and responses to the applicable third-party messaging platform. Such transmissions are directed by User and do not constitute Heureka Labs disclosures for Heureka Labs’s own purposes. The content of messages transmitted through Messaging Integrations is subject to the privacy policy and terms of service of the applicable third-party platform, and Heureka Labs has no control over how such platforms process, store, or use transmitted content. (d) Future Channels. Heureka Labs reserves the right to add additional Messaging Integration options or remove existing Messaging Integration options in the future. Heureka Labs will obtain separate opt-in consent from Users who wish to use new channels as they are offered. (e) CAN-SPAM and TCPA Compliance. Where a Messaging Integration involves the delivery of messages to User’s email address or mobile device, such messages constitute communications that User has affirmatively requested and consented to receive. Users may revoke consent for any Messaging Integration at any time through Platform settings. Revocation is effective prospectively and does not affect messages transmitted prior to revocation. For messages transmitted to mobile devices via SMS or equivalent channels, User represents that they are the account holder or authorized user of the mobile number provided. (f) No Warranty for Third-Party Channels. Heureka Labs makes no representations regarding the reliability, security, availability, or data practices of any third-party messaging platform. Heureka Labs is not responsible for the failure of any Messaging Integration due to third-party platform changes, API restrictions, or service interruptions. (g) Disabling Integrations. User may disconnect any Messaging Integration at any time through Platform settings. Disconnection does not delete message history from the third-party platform, which is governed solely by that platform’s own policies. 5.14 Visual Capture and Image-to-Text Features. (a) Description. The Platform supports optional integration with Visual Capture Features. Visual Capture Features may include optical character recognition (“OCR”), scene description, document digitization, and contextual annotation of visual content, which is then processed and added to the User’s Platform instance. (b) Opt-In Required. All Visual Capture Features are opt-in only and require affirmative User authorization through Platform settings prior to activation. User may revoke authorization at any time through Platform settings or through device-level permission controls. (c) Local vs. Cloud Processing. Visual content captured through Visual Capture Features may be processed locally on User’s device or transmitted to Heureka Labs’s cloud infrastructure for processing, depending on the feature and User’s settings. Where cloud processing is used, image data will be stored in encrypted environments, processed for the purposes described in this Section, and deleted from active cloud storage within thirty (30) days of processing completion, except where User has explicitly enabled cloud storage of visual content. (d) No Biometric Processing. Heureka Labs does not use Visual Capture Features to identify, profile, or authenticate individuals by their physical characteristics. Visual content transmitted to the Platform is processed solely for the purpose of extracting text, research-relevant visual information, or contextual data for the User’s Platform instance. Users must not use Visual Capture Features to capture, process, or upload images of individuals without their knowledge and consent. Users located in jurisdictions with biometric privacy laws must not use Visual Capture Features in any manner that results in the capture or transmission of biometric identifiers or biometric information as defined under applicable law. User’s indemnification obligations under Section 12.1 of the Terms of Service extend to any claim arising from User’s use of Visual Capture Features in violation of applicable biometric privacy laws. (e) User Responsibilities. User is solely responsible for: (i) obtaining all necessary consents from individuals who may appear in or be identifiable from captured visual content; (ii) complying with applicable laws governing the capture and processing of images and visual data, including laws regulating biometric data, workplace monitoring, and recording consent in the User’s jurisdiction; and (iii) ensuring that visual content uploaded to the Platform does not include protected health information, PHI, or special category personal data in violation of Section 4.5 of the Terms of Service. (f) Third-Party Hardware. Heureka Labs makes no warranty regarding the performance, accuracy, security, or regulatory compliance of third-party hardware used in connection with Visual Capture Features. All disclaimers in Section 5.6(c) apply in full to Visual Capture Integrations. 5.15 Context Consolidation. (a) Description. The Platform may periodically perform context consolidation operations (“Consolidation Runs”) that automatically summarize, package, and restructure accumulated session history, agent interaction logs, notes, and other User-generated context within a User’s account into a condensed, structured format suitable for consumption by the Platform’s AI agents (“Consolidated Context”). Consolidation Runs are designed to maintain the Platform’s operational effectiveness as the volume of accumulated context in a User’s account grows over time. (b) Automated Nature. Consolidation Runs are performed automatically by the Platform. Heureka Labs will provide Users with notice in Platform settings that Consolidation Runs are enabled by default, and Users may configure the frequency or disable automatic Consolidation Runs through Platform settings. Disabling Consolidation Runs may cause the Platform’s AI agents to operate with reduced contextual awareness and spend more Credits for operations as accumulated context volume increases. (c) Data Handling. Consolidation Runs operate on User Data already stored within the User’s Platform account. Consolidated Context is stored within the User’s account as a derived representation and is subject to the same privacy protections and retention policies as other User Data in the account. Consolidation Runs do not transmit raw User Data to third parties and do not use User Data for AI model training. (d) Credit Consumption. Consolidation Runs consume Credits. Where a Consolidation Run is triggered automatically, Credit consumption will be deducted from the User’s account balance at the time of the Consolidation Run. Heureka Labs is not obligated to refund Credits consumed by automated Consolidation Runs as further described in Terms Section 3.2. 5.16 SFTP File Transfer. (a) Description. Heureka Labs may offer a Secure File Transfer Protocol (“SFTP”) interface that allows Users to transfer large data files directly to Heureka Labs’s cloud storage infrastructure (“SFTP Transfer”). SFTP Transfer is an opt-in feature available to Users with accounts in good standing and sufficient storage allocation. (b) Authentication and Security. Users must authenticate to the SFTP interface using credentials issued by Heureka Labs and/or share relevant information including but not limited to SSH key pairs, access tokens, addresses, credentials, or other authentication mechanisms with Heureka Labs. User is solely responsible for maintaining the security of SFTP credentials and for all file transfer activity conducted under their SFTP credentials. Users must immediately notify Heureka Labs at support@heurekalabs.co upon discovering or suspecting unauthorized use of their SFTP credentials. Files uploaded via SFTP are stored on Heureka Labs’s cloud infrastructure using encryption at rest consistent with Heureka Labs’s standard security practices as described in Section 6 of the Privacy Policy. (c) User Responsibilities. User is solely responsible for: (i) ensuring that all data transferred via SFTP complies with the User Data warranties in EULA Section 4.6 and the prohibitions in Terms Section 4.5 (including the prohibition on PHI and PII); (ii) ensuring that SFTP transfers comply with all applicable export control laws and regulations, including ITAR and EAR; (iii) verifying the integrity and completeness of transferred files following upload; and (iv) maintaining backups of all data transferred via SFTP, as Heureka Labs’s standard backup processes may not immediately capture newly uploaded SFTP files. (d) Storage and Fees. Files uploaded via SFTP are subject to the storage terms in Terms Section 3.3 and the retention policies in Terms Section 4.7. Large file uploads may trigger storage fees as described in Terms Section 3.3. (e) No Warranty of Transmission Integrity. Heureka Labs implements commercially reasonable measures to ensure the integrity of SFTP transmissions but does not guarantee that all files will transfer without error, corruption, or interruption. User is responsible for verifying file integrity after upload. (f) Prohibited Content. SFTP Transfer may not be used to upload executable code, scripts, or compiled binaries that are not explicitly authorized by Heureka Labs in writing. Heureka Labs reserves the right to inspect, quarantine, or delete any file uploaded via SFTP that Heureka Labs reasonably determines poses a security risk. 5.17 Company Disclaimer and User Responsibility. HEUREKA LABS IS NOT RESPONSIBLE FOR ANY LOSS, CORRUPTION, DELETION, OR ERRONEOUS MODIFICATION OF LOCAL FILES, DATA, OR SYSTEM CONFIGURATIONS ARISING FROM PLATFORM OR AGENT OPERATIONS ON USER’S LOCAL DEVICE OR CLOUD ENVIRONMENT, WHETHER CAUSED BY PLATFORM ERROR, AGENT-GENERATED CODE EXECUTION, OR USER ERROR EXCEPT IN CASES OF GROSS NEGLIGENCE OR WILLFUL MISCONDUCT. PLATFORM IS INTENDED SOLELY FOR PROFESSIONAL AND INSTITUTIONAL RESEARCH USE. USER IS SOLELY RESPONSIBLE FOR MAINTAINING ADEQUATE BACKUPS OF ALL LOCAL FILES. FILES STORED ON USER’S LOCAL DEVICE ARE OUTSIDE HEUREKA LABS’S CONTROL AND RESPONSIBILITY.

  6. AI OUTPUTS AND SCIENTIFIC DISCLAIMER 6.1 Outputs Are Not Validated. ALL OUTPUTS GENERATED BY THE PLATFORM, INCLUDING BUT NOT LIMITED TO ANALYSES, SUMMARIES, CODE, EXPERIMENTAL RECOMMENDATIONS, AND ANY OTHER RESULTS, ARE PROVIDED FOR INFORMATIONAL AND RESEARCH SUPPORT PURPOSES ONLY. OUTPUTS HAVE NOT BEEN PEER-REVIEWED, INDEPENDENTLY VALIDATED, OR CERTIFIED AS SCIENTIFICALLY ACCURATE. 6.2 User Verification Responsibility. User is solely responsible for independently verifying all Outputs for scientific validity, accuracy, completeness, and fitness for any particular purpose before relying upon them. Outputs are not a substitute for expert scientific judgment, professional expertise, or peer review. 6.3 EU AI Act. The EU AI Act (Regulation (EU) 2024/1689) establishes requirements for artificial intelligence systems placed on the EU market. Heureka Labs will make commercially reasonable efforts to meet these requirements, including marking AI-generated content, ensuring both Company and third-party general-purpose AI (“GPAI”) providers fulfill their obligations under Article 53 requirements, and assessing if the Platform deployment constitutes a high-risk AI system. Heureka Labs does not represent that the Platform constitutes a high-risk AI system within the meaning of the EU AI Act. Users who deploy the Platform in research or operational contexts that may constitute high-risk AI use within the meaning of Annex III of the EU AI Act are solely responsible for assessing their own compliance obligations thereunder, including any obligations that may attach to them as deployers of AI systems. Users may not use the Platform for any purpose that constitutes a prohibited AI practice under AI Act Article 5, including but not limited to: (i) AI systems that deploy subliminal techniques to materially distort behavior; (ii) AI systems that exploit vulnerabilities of specific groups; (iii) social scoring systems; (iv) real-time remote biometric identification systems in publicly accessible spaces (subject to AI Act exceptions); or (v) any other practice prohibited under Article 5, as may be amended. Any such use constitutes a material breach of this EULA and the Terms of Service. Heureka Labs monitors EU AI Act obligations as they apply to the Platform and will provide Users with relevant information upon request. Requests should be sent to support@heurekalabs.co. Nothing in this EULA constitutes legal advice regarding a User’s obligations under the EU AI Act. 6.4 No Warranty of Accuracy. HEUREKA LABS DOES NOT WARRANT THAT THE PLATFORM WILL PRODUCE ACCURATE, COMPLETE, RELIABLE, OR ERROR-FREE OUTPUTS. AI MODELS MAY PRODUCE OUTPUTS THAT CONTAIN ERRORS, FABRICATIONS, OR INCONSISTENCIES (COMMONLY REFERRED TO AS “HALLUCINATIONS”). USER ASSUMES ALL RISK ARISING FROM RELIANCE ON PLATFORM OUTPUTS. 6.5 Regulatory Submissions and Regulated Research Contexts. (a) OUTPUTS MUST NOT BE SUBMITTED TO ANY REGULATORY AUTHORITY AS PRIMARY EVIDENCE WITHOUT INDEPENDENT EXPERT VALIDATION AND VERIFICATION BY QUALIFIED PERSONNEL RESPONSIBLE FOR THE SUBMISSION. THIS INCLUDES ANY REGULATED RESEARCH OR CLINICAL CONTEXT, INCLUDING BUT NOT LIMITED TO: INVESTIGATIONAL NEW DRUG (“IND”) APPLICATIONS; NEW DRUG APPLICATIONS (“NDAs”), BIOLOGICS LICENSE APPLICATIONS (“BLAs”), PREMARKET APPROVAL APPLICATIONS (“PMAs”), OR 510(k) SUBMISSIONS TO THE U.S. FOOD AND DRUG ADMINISTRATION (“FDA”); MARKETING AUTHORIZATION APPLICATIONS (“MAAs”) OR OTHER SUBMISSIONS TO THE EUROPEAN MEDICINES AGENCY (“EMA”) OR EQUIVALENT REGULATORY BODIES; CE MARKING TECHNICAL FILES; OR SUBMISSIONS TO ANY NATIONAL MEDICINES REGULATORY AUTHORITY. THE PLATFORM AND ITS OUTPUTS HAVE NOT BEEN VALIDATED, AUDITED, QUALIFIED, OR APPROVED FOR USE IN SUCH CONTEXTS. (b) GxP Environments. The Platform is not designed, tested, or validated as a GxP system (including GMP, GLP, GCP, or GDP environments) within the meaning of FDA regulations (including 21 CFR Parts 11, 210, 211, and 312), EMA guidelines, ICH guidelines, or equivalent international standards. Users who deploy the Platform in connection with activities subject to GxP requirements are solely responsible for: (i) conducting appropriate system qualification and validation assessment (including IQ, OQ, and PQ testing as applicable) prior to any GxP use; (ii) establishing and maintaining audit trails, change control procedures, and documentation practices consistent with applicable GxP requirements; (iii) determining whether the Platform’s electronic records and electronic signature features meet 21 CFR Part 11 or equivalent requirements for their specific use; and (iv) independently verifying all Platform-assisted conclusions prior to reliance in any GxP-regulated process. (c) AI/ML Regulatory Guidance. Users who use the Platform to develop, train, validate, or support the use of AI/ML-based software as a medical device (“SaMD”) or in connection with clinical decision support tools should consult applicable FDA guidance (including the FDA Action Plan for AI/ML-Based SaMD and Predetermined Change Control Plan guidance), EMA Reflection Paper on the Use of Artificial Intelligence in the Lifecycle of Medicines, and equivalent guidance documents. Heureka Labs makes no representation that the Platform satisfies any requirement of such guidance and does not provide regulatory affairs advice. (d) User Responsibility. Users operating in regulated research or clinical environments are solely responsible for: (i) engaging qualified regulatory affairs counsel and scientific personnel to evaluate Platform Outputs prior to any regulatory submission; (ii) compliance with all applicable regulatory frameworks, including data integrity, audit trail, and documentation requirements; (iii) understanding and managing risks associated with AI-generated content in regulated contexts, including hallucination, bias, and inconsistency as described in Section 6.4; and (iv) determining whether their specific Platform use requires notification, approval, or qualification from any regulatory authority. (e) No Regulatory Endorsement. Nothing in this Agreement, and no aspect of the Platform’s design or functionality, constitutes or should be construed as a representation by Heureka Labs that the Platform satisfies any regulatory requirement or is appropriate for any regulated purpose. Heureka Labs does not hold any regulatory clearance, approval, or qualification with respect to the Platform. 6.6 AI-Generated Code in User Deliverables and Publications. (a) No Warranty for Incorporated Code. Outputs generated by the Platform may include code, scripts, algorithms, or software components (“AI-Generated Code”). Heureka Labs makes no warranty, express or implied, regarding the correctness, security, reliability, fitness for purpose, or absence of errors, vulnerabilities, or unintended behaviors in any AI-Generated Code, including AI-Generated Code that User incorporates into research deliverables, publications, software products, tools, or other downstream works (collectively, “User Deliverables”). (b) User Responsibility for Incorporated Code. User is solely responsible for: (i) independently reviewing, testing, validating, and auditing all AI-Generated Code before incorporating it into any User Deliverable or making it available to third parties; (ii) ensuring that AI-Generated Code incorporated into User Deliverables does not infringe any third-party intellectual property rights; (iii) complying with all applicable open-source license obligations, export control requirements, and regulatory standards applicable to software in User’s research or commercial context; and (iv) any harm, loss, liability, or damage arising from the execution, distribution, or use of AI-Generated Code incorporated into User Deliverables by User or any third party. (c) Downstream Harm Disclaimer. HEUREKA LABS SHALL NOT BE LIABLE FOR ANY HARM, LOSS, DAMAGE, OR LIABILITY ARISING FROM: (i) THE EXECUTION OF AI-GENERATED CODE BY USER OR ANY THIRD PARTY; (ii) THE INCORPORATION OF AI-GENERATED CODE INTO ANY USER DELIVERABLE, SOFTWARE PRODUCT, RESEARCH PUBLICATION, OR OTHER DOWNSTREAM WORK; OR (iii) ANY SECURITY VULNERABILITY, BUG, ERROR, OR UNINTENDED BEHAVIOR IN AI-GENERATED CODE WHEN EXECUTED OR DEPLOYED OUTSIDE OF THE PLATFORM. THIS DISCLAIMER APPLIES REGARDLESS OF WHETHER USER HAS REVIEWED OR TESTED THE AI-GENERATED CODE PRIOR TO INCORPORATION. (d) Publication Disclosure. Where User incorporates AI-Generated Code into a published research work or open-source software release, User is encouraged to disclose such use in accordance with applicable journal policies and the platform use disclosure obligations in Terms of Service Section 6.5.

  7. UPDATES AND MODIFICATIONS TO SOFTWARE 7.1 Automatic Updates; User Delay Option; Security Responsibility. (a) Default Auto-Update. The Software is configured to check for and download available updates, patches, bug fixes, and new versions (“Updates”) automatically. By default, Updates are applied automatically. The Software may also prompt User to restart or close the application to complete installation of a pending Update. Heureka Labs recommends that User keep the Software up to date at all times to ensure access to the latest features, performance improvements, and security fixes. (b) User Delay Option. User may delay the installation of any pending Update through the Software’s settings. There is no limit on the number of times User may delay any single Update from the offered delay periods. Heureka Labs does not force installation of Updates without User consent, except as described in Section 7.1(c). (c) Critical Security Updates and AI Feature Restriction. Notwithstanding Section 7.1(b), Heureka Labs reserves the right to designate certain Updates as critical security updates (“Critical Updates”) in the event of a confirmed or reasonably suspected material functional issue or security vulnerability affecting the Platform’s AI features, model inference, or data processing capabilities. A Critical Update qualifies as such where the unaddressed vulnerability poses an immediate and material risk to Platform integrity, User data, or the data of other Platform users, as determined by Heureka Labs in its reasonable judgment. For Critical Updates: (i) Heureka Labs will provide User with prominent in-application notice of the Critical Update, the nature of the vulnerability addressed, and the date by which installation is required to maintain full Platform access (“Critical Update Deadline”), which shall be no fewer than seven (7) days from the date of notice except where an emergency requiring immediate action exists, in which case Heureka Labs shall provide such advance notice as is reasonably practicable under the circumstances, and in any event shall notify User of the restriction and its basis concurrently with or immediately following implementation; (ii) if User has not installed the Critical Update by the Critical Update Deadline, Heureka Labs may, in its reasonable discretion, restrict User’s access to AI-powered features of the Platform (including but not limited to AI model inference, agent operations, and AI-assisted data analysis) until the Critical Update is installed, while maintaining User’s access to non-AI Platform features such as data storage, file management, account administration, and data download; (iii) Heureka Labs will provide User with notice of any such AI feature restriction at the time it takes effect; and (iv) full AI feature access will be automatically restored upon installation of the Critical Update. Heureka Labs’s exercise of this restriction right does not constitute a suspension or termination of User’s account and does not trigger Credit refund obligations. Heureka Labs shall not be liable for any loss, research interruption, or other harm arising from AI feature restrictions imposed pursuant to this Section. (d) Liability for Outdated Software. Heureka Labs’s security obligations, representations, and warranties with respect to the Software apply only to the most recent generally available version of the Software and to any version that has not yet had a successor Update available for at least fourteen (14) days. In addition to the liability limitation set forth below, and independently of such limitation, Heureka Labs reserves the right to restrict AI feature access pursuant to Section 7.1(c) where a Critical Update has been available and the applicable Critical Update Deadline has passed without User having installed the Critical Update. Such restriction is a separate contractual right and is not conditioned on the liability limitations in this Section. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, HEUREKA LABS SHALL HAVE NO LIABILITY TO USER OR ANY THIRD PARTY FOR ANY LOSS, DAMAGE, DATA BREACH, SECURITY INCIDENT, VULNERABILITY EXPLOITATION, OR OTHER HARM ARISING FROM OR IN CONNECTION WITH USER’S CONTINUED USE OF A VERSION OF THE SOFTWARE FOR WHICH A SECURITY-RELEVANT UPDATE HAS BEEN AVAILABLE FOR MORE THAN FOURTEEN (14) DAYS AND WHICH HAS NOT BEEN INSTALLED ON USER’S DEVICE, REGARDLESS OF THE REASON FOR NON-INSTALLATION, INCLUDING BUT NOT LIMITED TO USER’S DECISION TO DELAY, INSUFFICIENT DEVICE STORAGE, UNSUPPORTED OPERATING SYSTEM OR HARDWARE, NETWORK UNAVAILABILITY, INSTITUTIONAL IT RESTRICTIONS, OR ANY OTHER TECHNICAL OR ADMINISTRATIVE OBSTACLE. This limitation applies regardless of whether User delayed the Update pursuant to Section 7.1(b) or (c) and regardless of whether User was notified of the Update. (e) Update Scope. All Updates are governed by this EULA unless a separate written agreement specifically accompanies the Update and supersedes it. If an Update materially changes the permissions, data practices, or agent behaviors described in this EULA or in Section 5, Heureka Labs will provide at least thirty (30) days’ notice via in-app notification and/or email prior to the effective date of such change, in accordance with Section 13.2. (f) Governing Agreement. This EULA and the Terms of Service govern all Updates unless a separate agreement accompanies an Update. 7.2 Heureka Labs reserves the right to modify, suspend, or discontinue any feature of the Software or Platform with at least thirty (30) days’ prior notice, except in cases of emergency security patches, legal compliance requirements, or other circumstances requiring immediate action. 7.3 Beta and Preview Features. (a) Designation. Heureka Labs may from time to time make available features, tools, agents, models, or functionality designated as “beta,” “preview,” “experimental,” “early access,” or similar (collectively, “Beta Features”). Beta Features are provided for testing and evaluation purposes and are not part of the generally available Platform. (b) No Warranty. BETA FEATURES ARE PROVIDED “AS IS” AND “AS AVAILABLE” WITHOUT ANY WARRANTY OF ANY KIND. THE DISCLAIMERS IN SECTION 9 OF THIS EULA APPLY IN FULL TO BETA FEATURES AND ARE EXPRESSLY REINFORCED: BETA FEATURES MAY CONTAIN BUGS, ERRORS, OR LIMITATIONS NOT PRESENT IN GENERALLY AVAILABLE PLATFORM FEATURES. HEUREKA LABS DOES NOT WARRANT THAT BETA FEATURES WILL ACHIEVE ANY PARTICULAR RESULT, OPERATE WITHOUT INTERRUPTION, OR FUNCTION COMPATIBLY WITH USER’S SYSTEMS OR DATA. (c) No Research Reliance. User acknowledges that Beta Features are not intended for use in production research workflows, regulatory submissions, clinical applications, or any context where errors or failure could cause material harm. User is solely responsible for any decision to rely on Outputs generated by Beta Features for any research or professional purpose. (d) Feedback. By using Beta Features, User may be invited to provide feedback, suggestions, or bug reports. Such feedback is governed by Section 5.6 of the Terms of Service. Heureka Labs is not obligated to act on feedback or to continue development of any Beta Feature. (e) Modification and Discontinuation. Heureka Labs may modify, suspend, or discontinue any Beta Feature at any time without notice and without liability. Credits consumed in connection with Beta Features are non-refundable. (f) Confidentiality. If Heureka Labs designates a Beta Feature as confidential at the time of access, User agrees to treat the existence, features, and capabilities of that Beta Feature as Heureka Labs Confidential Information under Section 3.2 of this EULA and not to disclose it to third parties without Heureka Labs’s prior written consent.

  8. TERM AND TERMINATION 8.1 Term. This EULA commences on the date User first installs or uses the Software and continues until terminated. 8.2 Termination and Suspension by Heureka Labs. (a) Termination with Notice. Heureka Labs may terminate this EULA and User’s license at any time, for any reason or no reason, upon thirty (30) days’ written notice to User. In the event of termination under this Section 8.2(a), User shall be entitled to the pro-rata Credit refund described in Section 8.4(e)(i), in addition to the continued access and Download Window rights described in Section 8.2(e)(i). (b) Immediate Termination Without Notice. Heureka Labs may terminate this EULA and User’s license immediately, without prior notice, upon the occurrence of any of the following: (i) Material breach of this EULA or the Terms of Service by User, including but not limited to violation of the restrictions in Section 3, breach of confidentiality obligations, or breach of any representation or warranty made herein; (ii) Suspected or confirmed unauthorized access to the Platform or User’s Account by User or a third party acting through User’s credentials; (iii) Confirmed or suspected security breach, compromise of authentication credentials, or any activity that Heureka Labs reasonably determines poses an immediate risk to the integrity, security, or availability of the Platform or to other users’ data; (iv) Violation of applicable law, including but not limited to export control laws, sanctions regulations, data protection laws, or research regulatory requirements; (v) Conduct that Heureka Labs reasonably determines poses an immediate risk of harm to other Users, third parties, or the Platform; (vi) Use of the Platform for any prohibited research activity listed in Section 6.1 of the Terms of Service; (vii) Any attempt to reverse engineer, decompile, extract model weights, engage in prompt injection, or circumvent the Platform’s security measures or intellectual property protections, as further described in Section 3 of this EULA and Section 7.4 of the Terms of Service; (viii) Heureka Labs having reasonable grounds to believe that User has provided materially false, misleading, or fraudulent information in connection with account registration, identity, institutional affiliation, eligibility, sanctions status, or any representation or warranty made under this EULA or the Terms of Service, consistent with Section 7.6 of the Terms of Service; or (ix) Violation of the Prohibited AI Misuse and Data Abuse provisions of Section 6.7 of the Terms. (c) Suspension Pending Investigation. Without limiting Heureka Labs’s termination rights, Heureka Labs may suspend User’s access to the Software and Platform immediately, with or without notice, pending investigation of any circumstance that could give rise to termination under Section 8.2(b). Suspension may include restriction of login access, freezing of Credits, and disabling of agent and computational features. Heureka Labs will make commercially reasonable efforts to notify User of a suspension and the general basis for it within a reasonable time, except where notification would compromise an ongoing security investigation or is otherwise prohibited by applicable law. Suspension does not constitute a waiver of Heureka Labs’s right to subsequently terminate under this Section. (d) Consequences of Termination. Termination under this Section 8.2 is in addition to, and does not limit, Heureka Labs’s rights under Section 8.4 (Effect of Termination) or any other rights or remedies available to Heureka Labs at law or in equity. Upon termination for cause under Section 8.2(b), Heureka Labs may additionally: (i) Forfeit all unused Credits in the Account, which shall be non-refundable under Section 7.3 of the Terms of Service. For the avoidance of doubt, this forfeiture applies to termination for cause under this Section 8.2(b) only and not to termination under Section 8.2(a), for which the pro-rata refund described in Section 8.4(e)(i) applies; (ii) Deny User access to data generated in breach of this EULA or the Terms of Service; (iii) Pursue all available legal remedies, including claims for damages, injunctive relief, and recovery of costs and attorneys’ fees where permitted by law; and (iv) Disclose information regarding the Account and its activities to law enforcement, regulatory authorities, or affected third parties to the extent required or permitted by applicable law, including in connection with sanctions violations, export control violations, or confirmed security incidents. (e) No Liability for Termination or Suspension. Heureka Labs shall not be liable to User or any third party for any claim arising from the termination or suspension of User’s license or access under this Section, including any resulting loss of data, research, Credits, revenue, or business opportunity. This limitation applies whether termination or suspension was with or without notice and regardless of whether it was later determined to have been made in error. Notwithstanding the foregoing, the following limited exceptions apply: (i) Termination with Notice. Following delivery of a termination notice under Section 8.2(a): (A) User’s full Platform access (including the ability to initiate new tasks, consume Credits, and create new data) continues through the end of the twenty-five (25) day period following notice; (B) during the final five (5) days of the thirty (30) day notice period (“Download Window”), User’s access is restricted to read-only access and download of User Data stored on Heureka Labs’s cloud servers; and (C) at the end of the thirty (30) day notice period, all access terminates. The Download Window runs concurrently within the notice period and does not extend beyond the thirty (30) day notice period. (ii) Erroneous Immediate Termination. If Heureka Labs terminates User’s access under Section 8.2(b) and subsequently determines, in its sole reasonable judgment, that the termination was made in error (an “Erroneous Termination”), Heureka Labs shall: (A) promptly restore User’s access to the Platform; (B) reinstate the data access window described in Section 8.4(c) for a period of not less than five (5) calendar days from the date of reinstatement notification; (C) reinstate to User’s Account all Credits that were forfeited or frozen solely as a result of the Erroneous Termination and that had not been consumed prior to the erroneous termination event; and (D) use commercially reasonable efforts to restore access to User Data that had not been deleted from active Platform systems prior to Heureka Labs’s determination that the termination was erroneous. The foregoing obligations in clauses (A) through (D) constitute Heureka Labs’s complete satisfaction of any obligation arising from an Erroneous Termination. Heureka Labs shall have no obligation to: (1) compensate User for indirect, incidental, or consequential losses incurred during the termination period; (2) restore User Data deleted from active Platform systems in the ordinary course of operations prior to the error determination; or (3) restore Credits consumed (not forfeited) prior to or independent of the erroneous termination event. Nothing in this Section 8.2(e)(ii) requires Heureka Labs to reinstate an Account where the circumstances giving rise to the original termination, while not ultimately substantiated, were based on a reasonable good-faith assessment of potential breach at the time the decision was made. (iii) Wrongful Suspension. If a suspension under Section 8.2(c) is later determined to have been made without any reasonable basis, Heureka Labs shall promptly restore User’s access to the Platform and shall reinstate all Credits that were frozen solely as a result of the wrongful suspension. Heureka Labs shall have no further liability for losses incurred during the suspension period. 8.3 Termination by User. User may terminate this EULA at any time by uninstalling the Software and closing the Account. 8.4 Effect of Termination. Upon termination: (a) all licenses granted hereunder cease immediately; (b) User shall immediately uninstall and destroy all copies of the Software; (c) in cases of termination with notice under Section 8.2(a), User’s Download Window (the final five (5) days of the notice period) provides read-only access to download User Data stored on Heureka Labs’s cloud servers that User owns and that was not generated in breach of these Terms. In cases of immediate termination under Section 8.2(b), Heureka Labs will, at its sole discretion, provide a separate five (5) calendar day download window commencing upon notice of termination for data not generated in breach, except where the nature of the breach makes such access inappropriate (e.g., confirmed security incidents or sanctions violations); (d) data generated in violation of this EULA and/or the Terms of Service is not accessible post-termination, and Heureka Labs shall have no obligation to provide access to or copies of such data. Heureka Labs reserves the right to permanently delete data generated in breach of this EULA immediately upon termination, subject to any applicable legal hold, regulatory preservation, or law enforcement disclosure obligations. Heureka Labs’s exercise of this right shall not constitute a waiver of any claim arising from the breach; (e) Credits are non-refundable upon termination, except as follows: (i) Termination Without Cause. In the event of termination by Heureka Labs pursuant to Section 8.2(a), Heureka Labs shall refund to User a pro-rata portion of any Credits purchased by User within the ninety (90) days preceding the termination notice date that remain unused as of the effective termination date, calculated at the rate per Credit paid by User at the time of the applicable purchase. (ii) Required by Law. As required by applicable law, including California Business and Professions Code Section 17538.9 and applicable EU/UK consumer protection laws. (iii) Erroneous Termination. As provided in Section 8.2(e)(ii) with respect to Credits forfeited solely as a result of an Erroneous Termination. For the avoidance of doubt, no Credit refund is available upon: (A) termination for cause under Section 8.2(b); (B) Account closure initiated by User under Section 8.3; or (C) Account suspension under Section 8.2(c), which does not constitute a termination event; and (f) provisions that by their nature survive termination shall survive.

  9. DISCLAIMER OF WARRANTIES THE SOFTWARE AND PLATFORM ARE PROVIDED “AS IS” AND “AS AVAILABLE” WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, HEUREKA LABS EXPRESSLY DISCLAIMS ALL WARRANTIES, INCLUDING BUT NOT LIMITED TO IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, AND ANY WARRANTIES ARISING OUT OF COURSE OF DEALING OR USAGE OF TRADE. HEUREKA LABS DOES NOT WARRANT THAT THE SOFTWARE, AGENTS, OR CODE GENERATED BY AI WILL MEET USER’S REQUIREMENTS, OPERATE WITHOUT INTERRUPTION OR ERROR, OR THAT DEFECTS WILL BE CORRECTED. NO ORAL OR WRITTEN INFORMATION OR ADVICE GIVEN BY HEUREKA LABS OR ITS REPRESENTATIVES SHALL CREATE A WARRANTY. The disclaimer in this Section 9 and the limitations in Section 10 apply in full to any version of the Software for which a superseding Update has been available for more than thirty (30) days and which User has chosen not to install, consistent with Section 7.1(d).

  10. LIMITATION OF LIABILITY 10.1 EXCLUSION OF CONSEQUENTIAL DAMAGES. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL HEUREKA LABS, ITS OFFICERS, DIRECTORS, EMPLOYEES, AGENTS, LICENSORS, OR AFFILIATES BE LIABLE TO USER OR ORGANIZATION FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, PUNITIVE, OR EXEMPLARY DAMAGES, INCLUDING BUT NOT LIMITED TO LOSS OF DATA, LOSS OF FILES, LOSS OF RESEARCH, LOSS OF REVENUE, LOSS OF PROFITS, LOSS OF GOODWILL, OR COST OF SUBSTITUTE GOODS OR SERVICES, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. NOTWITHSTANDING THE FOREGOING, THIS EXCLUSION OF CONSEQUENTIAL DAMAGES AND THE AGGREGATE LIABILITY CAP IN SECTION 10.2 SHALL NOT APPLY TO: (A) BREACHES OF CONFIDENTIALITY OBLIGATIONS; OR (B) A PARTY’S GROSS NEGLIGENCE OR WILLFUL MISCONDUCT. FOR THE AVOIDANCE OF DOUBT, EACH PARTY’S INDEMNIFICATION OBLIGATIONS ARE SUBJECT TO THE AGGREGATE LIABILITY CAP IN SECTION 10.2 AND THE CONSEQUENTIAL DAMAGES EXCLUSION IN THIS SECTION 10.1, EXCEPT THAT THE CONSEQUENTIAL DAMAGES EXCLUSION SHALL NOT LIMIT A PARTY’S OBLIGATION TO INDEMNIFY THE OTHER PARTY AGAINST CONSEQUENTIAL DAMAGES ACTUALLY AWARDED BY A COURT OR ARBITRATOR TO A THIRD PARTY IN AN INDEMNIFIED CLAIM. 10.2 AGGREGATE LIABILITY CAP. HEUREKA LABS’S TOTAL CUMULATIVE LIABILITY TO USER FOR ALL CLAIMS ARISING UNDER OR RELATED TO THIS EULA, INCLUDING CLAIMS UNDER TERMS OF SERVICE SECTION 12.2 AND ANY INTELLECTUAL PROPERTY INDEMNIFICATION CLAIMS, WHETHER IN CONTRACT, TORT, STATUTE, OR OTHERWISE, SHALL NOT EXCEED THE TOTAL AMOUNT PAID BY USER TO HEUREKA LABS FOR CREDITS AND PLATFORM ACCESS IN THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM. THIS IS A SINGLE AGGREGATE CAP APPLYING TO ALL CLAIMS COMBINED, NOT PER INCIDENT OR PER CLAIM TYPE. THE APPLICABILITY OF THIS CAP TO INDEMNIFICATION CLAIMS IS GOVERNED BY SECTION 10.1 ABOVE. 10.3 Essential Basis of Bargain. User acknowledges that the limitations on liability in this Section 10 reflect a reasonable allocation of risk, taking into account the nature of the Platform, the Credits-based pricing model, and the mutual benefits of this Agreement, and that such limitations are an essential element of the basis of the bargain between the parties. Heureka Labs would not have entered into this Agreement absent User’s agreement to the limitations set forth herein.

  11. DISPUTE RESOLUTION 11.1 Governing Law. This EULA shall be governed by and construed in accordance with the laws of the State of Delaware, without regard to its conflict of law principles. 11.2 Arbitration. Except as provided in Section 11.3 and 11.4, all disputes, claims, or controversies arising out of or relating to this EULA or the breach, termination, or validity thereof shall be resolved by final and binding arbitration administered by the American Arbitration Association (“AAA”) under its Commercial Arbitration Rules, unless otherwise agreed to in writing by both parties. The arbitration shall be conducted by a single arbitrator, seated in Wilmington, Delaware. The language of arbitration shall be English. The arbitrator’s award shall be final and binding and may be entered as a judgment in any court of competent jurisdiction. 11.3 Class Action Waiver. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, USER WAIVES ANY RIGHT TO PARTICIPATE IN A CLASS ACTION LAWSUIT, CLASS-WIDE ARBITRATION, PRIVATE ATTORNEY GENERAL ACTION, OR ANY OTHER REPRESENTATIVE PROCEEDING. ALL CLAIMS MUST BE BROUGHT ON AN INDIVIDUAL BASIS. 11.4 Injunctive Relief. Either party may seek emergency injunctive or other equitable relief in any court of competent jurisdiction to prevent irreparable harm, including protection of intellectual property rights or confidential information, without waiving the right to arbitrate the underlying dispute. 11.5 Time Limitation. Any claim under this EULA must be brought within one (1) year after the cause of action arises, or it is permanently waived and barred, except to the extent a longer period is required by applicable law.

  12. EXPORT COMPLIANCE AND SANCTIONS 12.1 User Representations. User represents and warrants, at the time of account registration and on a continuing basis throughout the term of this Agreement, that User is not: (a) located in or ordinarily resident in a jurisdiction subject to a comprehensive U.S. embargo administered by the Office of Foreign Assets Control (“OFAC”), including but not limited to Cuba, Iran, North Korea, Syria, and the Crimea, Donetsk, and Luhansk regions of Ukraine, as such list may be updated by OFAC from time to time; (b) named on, or owned or controlled by a party named on, any U.S. government list of prohibited or restricted parties, including OFAC’s Specially Designated Nationals and Blocked Persons List, the U.S. Department of Commerce Entity List, or the U.S. Department of State Debarred Parties List; or (c) otherwise prohibited from receiving or using the Software under applicable U.S. or international export control or sanctions laws and regulations. 12.2 User Compliance Obligations. User agrees to comply with all applicable U.S. and international export control laws and regulations, including the Export Administration Regulations (EAR) and, where applicable, the International Traffic in Arms Regulations (ITAR). User is solely responsible for ensuring that: (a) all Authorized Participants and collaborators who access the Platform under User’s Account are eligible to receive access under applicable export control laws; (b) User Data uploaded to the Platform does not include controlled technical data requiring authorization for the access levels provided; and (c) User’s use of the Platform in connection with any government-funded research complies with applicable federal funding agency requirements regarding foreign national participation. 12.3 Heureka Labs Screening Measures. Heureka Labs implements commercially reasonable measures to screen for potential sanctions compliance issues, including geographic IP screening for comprehensively sanctioned jurisdictions and payment processing screening through its payment processor. User acknowledges that such screening measures are not exhaustive and that User’s own representations and compliance obligations are independent of and not reduced by Heureka Labs’s screening activities. 12.4 Change in Status. If User’s status under Sections 12.1 or 12.2 changes, or if User becomes aware of any information suggesting a potential compliance issue, User must immediately cease using the Platform and notify Heureka Labs at support@heurekalabs.co. 12.5 Consequences. Any breach of this Section 12 constitutes a material breach of this Agreement and grounds for immediate termination under Section 8.2(b)(iv). Heureka Labs reserves the right to disclose information about the Account and its activities to relevant government authorities in connection with confirmed or suspected export control or sanctions violations.
  13. GENERAL PROVISIONS 13.1 Entire Agreement. This EULA, together with the Terms of Service and Privacy Policy, constitutes the entire agreement between User and Heureka Labs regarding the Software. Where User or User’s Organization has entered into a separate Master Services Agreement (“MSA”) executed between Heureka Labs and User’s Organization or Statement of Work (“SOW”) pursuant to an MSA between Heureka Labs and User’s Organization for specific research projects, the terms of the MSA/SOW shall govern those specific engagements, and this EULA shall govern Software access. In the event of direct conflict between an MSA/SOW and this EULA on a topic governed by the MSA/SOW, the MSA/SOW shall control for that project. Applicable Promotional Terms, if applicable, constitute additional components of the agreement with respect to those specific programs in effect from time to time. 13.2 Amendment. Heureka Labs reserves the right to amend this EULA upon at least thirty (30) days’ prior notice via in-app notification and/or email. Continued use following the effective date of any amendment constitutes acceptance of any and all amendments. 13.3 Severability. If any provision is held invalid or unenforceable, it shall be modified to the minimum extent necessary to make it enforceable, and the remaining provisions shall continue in full force. 13.4 Waiver. Failure to enforce any right shall not constitute a waiver of future enforcement. 13.5 Assignment. User may not assign this EULA or any rights hereunder without the prior written consent of Heureka Labs. Heureka Labs may assign this EULA in connection with a merger, acquisition, or sale of substantially all of its assets. 13.6 Contact. Questions about this EULA may be directed to: Heureka Labs, Attn: EULA Requests, 1030 N Rogers Ln, Ste 121 PMB 2165, Raleigh, NC 27610, USA, support@heurekalabs.co. 13.7 Governing Language. This EULA, the Terms of Service, the Privacy Policy, and all related agreements are drafted and executed in the English language, which shall be the governing and controlling language for all purposes. If Heureka Labs provides a translation of any of these documents into any other language, such translation is provided for convenience only. In the event of any conflict, inconsistency, or ambiguity between the English version and any translation, the English version shall prevail and control in all respects. Heureka Labs makes no representation that any translation is accurate or complete.

By installing or using the Software, User acknowledges having read, understood, and agreed to be bound by this EULA.