Athena Privacy Policy
Effective date: 7 October 2026
Athena is a second-screen helper for Overwatch. It reads the game events that Overwolf provides, shows advice about your match, and, only if you turn it on, shares a summary of your finished matches with a database that other Athena users also contribute to. This page says exactly what Athena stores, where, for how long, and how to see it and delete it.
Athena is a fan project. It is not affiliated with or endorsed by Blizzard Entertainment. Overwatch is a trademark of Blizzard Entertainment, Inc.
Who is responsible
The controller of the shared database is Athena Team, run by David Stenman, Stockholm, Sweden. Contact: dev.athenateam@gmail.com.
The short version
- Out of the box, everything Athena itself stores stays on your computer.
- Athena looks up the other players in your lobby. Their names always go to the public OverFast service, and to our server if you entered an invite code. Your own match summaries are uploaded only if you turn on Share matches. You can turn that off again at any time.
- The shared database never holds a plain BattleTag or player name. Names are turned into a keyed hash (a pseudonymous id) before they are stored.
- If you paste a Discord webhook address in Settings, Athena posts a recap of each finished match to your own Discord channel. By default that post lists the players of both teams by name, as the game showed them. You can turn the names off in Settings.
- Matches are uploaded after they end, never during one. Nothing in the shared database can show what a player is doing right now.
- Athena never reads the game's memory and never sends input to the game. It only uses the game events that Overwolf provides.
What stays on your computer
Athena keeps these files in its data folder (on Windows, %APPDATA%\Athena). They are never sent anywhere by themselves. Athena does not delete them automatically; you can delete them yourself at any time.
- Recordings (
recordings/*.gep.jsonl): the raw game events Athena received during your matches. They contain the BattleTags or display names of the players in your lobby, exactly as the game reported them, plus heroes, kills, deaths, map and mode. - Advice log (
recordings/*.ledger.json, next to each recording): the calls Athena showed you during the match (swap, stay, pick, plan: the hero, the score and confidence behind it) and nothing about other players. It is deleted with the recordings. - Match summaries (
stats.json): one entry per finished match with map, mode, outcome, the heroes you played, fight samples, your final stats, and the names of your teammates as the game showed them. This feeds the Profile tab. - Settings (
settings.json,window.json): your role, your declared rank, hotkey, overlay layout, and where the window sits. If you set one, also your Discord webhook address (a secret: it is only ever used to post to Discord, and is never logged, uploaded or shown in the overlay) and whether player names go in the Discord post. - Sharing state (
uploader.json, the outbox folder): whether sharing is on, the install token the server gave you (see below), the version of this policy you agreed to when you turned sharing on and the date and time you did, and match summaries waiting to be uploaded. - Feedback (
feedback.json): the invite code you typed the first time you used the Feedback form, if you did not already have a sharing token. It is only used to send feedback. Deleting your data from Settings → Your data removes it. - Profile cache (
overfast-cache.json): public profile data of players in your lobbies (ranks and hero statistics), kept for up to six hours and refreshed when needed.
What is sent to the shared database (only if you opt in)
When Share matches is on, each finished match is turned into a summary and uploaded to Athena's server. The summary contains:
- the match: map, game mode and queue, duration, outcome as you saw it, number of rounds, and the UTC date (no clock time);
- the lobby: up to 12 players, each with their side, role, the heroes they played and for how long, the fights and kills in the match, and, for your own team only, final stats (damage, healing, kills, deaths and so on). Stats of the enemy team are never collected;
- you as the uploader: which player you were, your declared rank from Settings, the app version and a SHA-256 fingerprint of your local recording file (the recording itself is not uploaded);
- the advice log of the match: which calls Athena showed you (hero, score, confidence), whether you followed each one and how the fights went while it stood. Hero names and numbers only, no player is named;
- every player's BattleTag or display name as sent to the server, which is converted on arrival into a keyed hash (HMAC-SHA256 with a secret that is kept only on the server) and then discarded. The database stores that hash and a numeric id for it. Everything else in the database refers to the numeric id only.
The server also stores, per install:
- a random install token, as a SHA-256 hash only; the token itself stays on your computer;
- a SHA-256 hash of the invite code you used, and the invite's label (a name the inviter chose, so installs of one person can be found and revoked);
- the date the install was created, whether it was revoked, and how many uploads and lookups it made per day (to enforce daily limits).
Because the pseudonymous id of a player is stable, the same BattleTag in different matches leads to the same id. That is how the database can say "this player usually plays Ana". It is still personal data: whoever holds the server secret can compute the id of a given BattleTag. We say so plainly instead of calling it anonymous.
From the stored matches the server builds summaries per player id (hero play time, wins and losses) and statistics per rank band. A statistic is only shown to anyone if at least 10 different players are behind it.
Looking up the players in your lobby
If you have entered an invite code (so Athena has a token), Athena asks the server about the players in your current lobby, to show their hero history on the Live tab. For this it sends their BattleTags or display names. The server hashes them to look them up, and neither stores nor logs them. This happens whether or not Share matches is on.
Public profiles (OverFast)
For each player in your lobby, Athena asks the public OverFast service (overfast-api.tekrop.fr, run by a third party) for their public Overwatch profile (ranks and hero statistics). This sends that player's BattleTag to OverFast, whether or not you share matches. Private profiles return nothing. OverFast has its own policy; Athena does not control it. OverFast is an open-source project (github.com/TeKrop/overfast-api); it publishes no privacy policy that we could find (checked 5 October 2026).
Third parties
- Overwolf provides the runtime and the game events. Overwolf's own terms and privacy policy apply to what the Overwolf platform collects. This policy is an agreement between you and the controller named above, not with Overwolf. Athena does not share your email address, single-sign-on data or advertising data with Overwolf: it collects none and shows no ads. See Overwolf's privacy policy.
- Cloudflare hosts the server (Cloudflare Workers and the D1 database; the database is created with a Western Europe location hint) and this website (Cloudflare Pages). Like any host, Cloudflare processes technical data such as IP addresses when your computer talks to the server. Athena's server code does not read, store or log IP addresses. Cloudflare acts as our processor under its Data Processing Addendum, which covers transfers outside the EU/EEA with Standard Contractual Clauses; its own data handling is described in Cloudflare's privacy policy.
- OverFast, described above.
- Discord: Discord Rich Presence is switched off unless it has been configured on your computer. When it is on, Athena tells your local Discord app where you are (menus, hero select, in a match), the map, your own hero and how long. Discord then shows that to your friends. It never includes other players, scores or outcomes. Discord's own policy applies to what it does with it.
- Discord post after a match (optional, a webhook you set up): only if you paste a Discord webhook address in Settings, under After a match. Athena then sends one post per finished 5v5 role queue match, from your computer straight to Discord; it does not pass through our server. The post holds the result, map, mode and duration, your heroes and your own numbers. Unless you switch off Show player names in Discord posts (on by default), it also lists both teams: the names of the players exactly as the game showed them in that match; for your team their heroes and the final kills, deaths, assists, damage, healing and mitigation the game reports for your own team; for the enemy team only the heroes the game had revealed by the end (the game shows enemy heroes with a delay) and no numbers. Everyone who can read that channel sees those names, and Discord processes the post under its own policy. The post never pings anyone. Nothing is posted until you paste an address, and removing the address stops it. The Windows notification after a match, the logs and the uploads never contain player names.
- Overwolf update server: store builds check
electron-updates.overwolf.comfor new versions (the request carries the app version and channel, no personal data from Athena). - GitHub hosts the project and its issue tracker. If you use the feedback links in the Help tab, what you write is posted on GitHub under your GitHub account, under GitHub's policy. If you use the Feedback form in the app instead, our server posts what you wrote as an issue in our private repository (see "Sending feedback" below); you need no GitHub account.
Sending feedback
The Feedback form in the app (and the moments you flag during a match) sends what you choose to our server, which turns it into an issue in our private GitHub repository so we can read and answer it. Nothing is sent until you press Send, and each item is your own choice:
- what you type, and the quick rating if you tap one;
- the app version, your operating system's name and the tab that was open;
- if you tick it, a screenshot of the Athena window as it looked when you opened the form (you see it before you send it). It can show the names of the players in your lobby, as the game showed them, if the Players panel was open;
- if you tick it, the recording of one match, with the other players' names and BattleTags replaced by Player1, Player2 and so on on your computer before it leaves it. Your own name becomes You;
- the label of your invite code or install (a name we chose, such as your first name) and a daily counter, to stop abuse.
The screenshot and the recording are kept on our server for 30 days and then deleted; the issue text stays in our private repository until we delete it. Ask us to delete a feedback item by emailing dev.athenateam@gmail.com. The lawful basis is your consent for each item (Art. 6(1)(a)).
Why we may process this (lawful basis)
- Your own data as an uploader: your consent (Art. 6(1)(a)). Sharing is off until you tick the box that says you have read this policy and agree, and enter an invite code. Athena keeps the policy version and the date of your tick on your computer as proof of consent. You can withdraw consent by turning sharing off. If this policy changes in a way that matters, uploads pause until you agree to the new version. Turning it off stops further uploads. Data already uploaded stays until you delete it (see below).
- Other players seen in your lobbies: these people never installed Athena and cannot consent. We rely on our legitimate interest in building match and hero statistics (Art. 6(1)(f)). We keep only what the game shows to everyone in the same match, stored under a pseudonymous id, never the BattleTag itself, and anyone can object and have their data deleted (see below). Players aged 13 to 17 can be in a lobby too: we collect nothing beyond what the match shows everyone, show no individual data publicly, and honour an objection at once. The written balancing test is in the project documentation (
docs/decisions/0004-gdpr-minimum.md), and you can ask us for it. - Install records and daily counters (the token hash, the invite label, the date, and the daily upload and lookup counts): our legitimate interest in running the service within its limits and revoking abuse (Art. 6(1)(f)).
- Looking up the players in your lobby: the same legitimate interest as for other players seen in your lobbies. The server hashes the name to look it up and neither stores nor logs it.
- Sending a lobby player's name to OverFast: legitimate interest. The profile is public on Blizzard's site, and a private profile returns nothing.
- Other players' names in your own Discord post: you decide, by pasting a webhook address and by leaving the names switch on. Athena sends the names the game showed everyone in that match to the channel you chose, on your behalf; we receive nothing and keep no copy. Turn the names off and they are not sent.
- Sharing is voluntary and Athena works without it. We make no decisions about you by automated means.
- Where the data about other players comes from: from an Athena user's game, through the game events Overwolf provides. These players have no relationship with Athena. We hold no contact details for them, so we cannot tell them individually (Art. 14(5)(b)); this page is the notice.
Your right to object
You can object at any time to us storing you as a player seen in someone else's match (Art. 21 GDPR). Email dev.athenateam@gmail.com with your full BattleTag. We stop and delete, and you do not need to give a reason. You can also ask us for the written balancing test behind our legitimate interest.
If you object or ask us to delete your data, we keep a keyed hash of your BattleTag (never the BattleTag itself) on a block list, so that later matches do not add you again. That hash is the only thing we keep. Tell us if you want to be taken off the list.
How long data is kept
- On your computer: until you delete it.
- In the shared database: while a player keeps appearing in uploaded matches we keep that player's pseudonymous history. 24 months after the last appearance we delete the player's id and all per-player rows. You can ask for earlier deletion at any time. Anonymous statistics computed from many players (for example the ranges shown under "Versus your rank") do not identify anyone and are kept.
- Backups: the database is exported weekly to a private store and each export is kept for 30 days. Cloudflare's own point-in-time recovery covers 7 days. Data you delete is gone from backups when they expire.
Your rights
Under the GDPR you have the right to access, correct and delete your personal data, to restrict or object to its processing, to withdraw consent, and to receive your data in a portable format.
- In the app: Settings → Your data shows what the shared database holds from your own uploads and lets you delete it. It does not remove you from matches that other people uploaded: for that, email us your BattleTag (see below).
- Without the app, or if you are a player who appeared in someone else's lobby: email dev.athenateam@gmail.com with your full BattleTag. We compute the pseudonymous id of that BattleTag, tell you what is held, and delete it on request. Because a deletion can only remove data, we delete or stop on request without asking you to prove you own the BattleTag. For a copy of your data we first send what the lookup feature already shows any Athena user (number of matches, last seen, top heroes). If you can show that the BattleTag is yours, we send the full record.
- Time limit: we answer within one month. If we have reasonable doubt that a request comes from the person it concerns, we may ask you to confirm it (Art. 12(6)).
- Local files: delete them yourself from the data folder; nothing else is needed.
- Complaints: you may complain to the data protection authority. For a controller in Sweden that is Integritetsskyddsmyndigheten (IMY).
Children
Turning on match sharing requires you to be at least 13 years old, or the age of digital consent in your country if it is higher. If you are younger, do not turn on sharing.
If something goes wrong
If a security incident puts your data at risk, we will tell you and the supervisory authority as the law requires.
Changes
When this policy changes in a way that matters, the effective date above changes and the new text is published at the same address. We also show a notice in the app at least 30 days before a material change takes effect.
Contact
dev.athenateam@gmail.com