Athena Privacy Policy
Effective date: 5 October 2026
Athena is a second-screen helper for Overwatch 2. It reads the game events that Overwolf provides, shows advice about your match, and, only if you turn it on, shares a summary of your finished matches with a database that other Athena users also contribute to. This page says exactly what Athena stores, where, for how long, and how to see it and delete it.
Athena is a fan project. It is not affiliated with or endorsed by Blizzard Entertainment. Overwatch is a trademark of Blizzard Entertainment, Inc.
Who is responsible
The controller of the shared database is Athena Team, run by David Stenman, Stockholm, Sweden. Contact: dev.athenateam@gmail.com.
The short version
- Out of the box, everything Athena itself stores stays on your computer.
- Athena looks up the other players in your lobby. Their names always go to the public OverFast service, and to our server if you entered an invite code. Your own match summaries are uploaded only if you turn on Share matches. You can turn that off again at any time.
- The shared database never holds a plain BattleTag or player name. Names are turned into a keyed hash (a pseudonymous id) before they are stored.
- Matches are uploaded after they end, never during one. Nothing in the shared database can show what a player is doing right now.
- Athena never reads the game's memory and never sends input to the game. It only uses the game events that Overwolf provides.
What stays on your computer
Athena keeps these files in its data folder (on Windows, %APPDATA%\Athena). They are never sent anywhere by themselves. Athena does not delete them automatically; you can delete them yourself at any time.
- Recordings (
recordings/*.gep.jsonl): the raw game events Athena received during your matches. They contain the BattleTags or display names of the players in your lobby, exactly as the game reported them, plus heroes, kills, deaths, map and mode. - Match summaries (
stats.json): one entry per finished match with map, mode, outcome, the heroes you played, fight samples, your final stats, and the names of your teammates as the game showed them. This feeds the Profile tab. - Settings (
settings.json,window.json): your role, your declared rank, hotkey, overlay layout, and where the window sits. - Sharing state (
uploader.json, the outbox folder): whether sharing is on, the install token the server gave you (see below), and match summaries waiting to be uploaded. - Profile cache (
overfast-cache.json): public profile data of players in your lobbies (ranks and hero statistics), kept for up to six hours and refreshed when needed.
What is sent to the shared database (only if you opt in)
When Share matches is on, each finished match is turned into a summary and uploaded to Athena's server. The summary contains:
- the match: map, game mode and queue, duration, outcome as you saw it, number of rounds, and the UTC date (no clock time);
- the lobby: up to 12 players, each with their side, role, the heroes they played and for how long, the fights and kills in the match, and, for your own team only, final stats (damage, healing, kills, deaths and so on). Stats of the enemy team are never collected;
- you as the uploader: which player you were, your declared rank from Settings, the app version and a SHA-256 fingerprint of your local recording file (the recording itself is not uploaded);
- every player's BattleTag or display name as sent to the server, which is converted on arrival into a keyed hash (HMAC-SHA256 with a secret that is kept only on the server) and then discarded. The database stores that hash and a numeric id for it. Everything else in the database refers to the numeric id only.
The server also stores, per install:
- a random install token, as a SHA-256 hash only; the token itself stays on your computer;
- a SHA-256 hash of the invite code you used, and the invite's label (a name the inviter chose, so installs of one person can be found and revoked);
- the date the install was created, whether it was revoked, and how many uploads and lookups it made per day (to enforce daily limits).
Because the pseudonymous id of a player is stable, the same BattleTag in different matches leads to the same id. That is how the database can say "this player usually plays Ana". It is still personal data: whoever holds the server secret can compute the id of a given BattleTag. We say so plainly instead of calling it anonymous.
From the stored matches the server builds summaries per player id (hero play time, wins and losses) and statistics per rank band. A statistic is only shown to anyone if at least 10 different players are behind it.
Looking up the players in your lobby
If you have entered an invite code (so Athena has a token), Athena asks the server about the players in your current lobby, to show their hero history on the Live tab. For this it sends their BattleTags or display names. The server hashes them to look them up, and neither stores nor logs them. This happens whether or not Share matches is on.
Public profiles (OverFast)
For each player in your lobby, Athena asks the public OverFast service (overfast-api.tekrop.fr, run by a third party) for their public Overwatch profile (ranks and hero statistics). This sends that player's BattleTag to OverFast, whether or not you share matches. Private profiles return nothing. OverFast has its own policy; Athena does not control it. OverFast is an open-source project (github.com/TeKrop/overfast-api); it publishes no privacy policy that we could find (checked 5 October 2026).
Third parties
- Overwolf provides the runtime and the game events. Overwolf's own terms and privacy policy apply to what the Overwolf platform collects. This policy is an agreement between you and the controller named above, not with Overwolf. Athena does not share your email address, single-sign-on data or advertising data with Overwolf: it collects none and shows no ads. See Overwolf's privacy policy.
- Cloudflare hosts the server (Cloudflare Workers and the D1 database; the database is created with a Western Europe location hint) and this website (Cloudflare Pages). Like any host, Cloudflare processes technical data such as IP addresses when your computer talks to the server. Athena's server code does not read, store or log IP addresses. Cloudflare acts as our processor under its Data Processing Addendum, which covers transfers outside the EU/EEA with Standard Contractual Clauses; its own data handling is described in Cloudflare's privacy policy.
- OverFast, described above.
- Discord: Discord Rich Presence is switched off unless it has been configured on your computer. When it is on, Athena tells your local Discord app where you are (menus, hero select, in a match), the map, your own hero and how long. Discord then shows that to your friends. It never includes other players, scores or outcomes. Discord's own policy applies to what it does with it.
- Overwolf update server: store builds check
electron-updates.overwolf.comfor new versions (the request carries the app version and channel, no personal data from Athena). - GitHub hosts the project and its issue tracker. If you use the feedback links in the Help tab, what you write is posted on GitHub under your GitHub account, under GitHub's policy.
Why we may process this (lawful basis)
- Your own data as an uploader: your consent (Art. 6(1)(a)). Sharing is off until you turn it on and enter an invite code, and you can withdraw consent by turning it off. Turning it off stops further uploads. Data already uploaded stays until you delete it (see below).
- Other players seen in your lobbies: these people never installed Athena and cannot consent. We rely on our legitimate interest in building match and hero statistics (Art. 6(1)(f)). We keep only what the game shows to everyone in the same match, stored under a pseudonymous id, never the BattleTag itself, and anyone can object and have their data deleted (see below). Players aged 13 to 17 can be in a lobby too: we collect nothing beyond what the match shows everyone, show no individual data publicly, and honour an objection at once. The written balancing test is in the project documentation (
docs/decisions/0004-gdpr-minimum.md), and you can ask us for it. - Where the data about other players comes from: from an Athena user's game, through the game events Overwolf provides. These players have no relationship with Athena. We hold no contact details for them, so we cannot tell them individually (Art. 14(5)(b)); this page is the notice.
Your right to object
You can object at any time to us storing you as a player seen in someone else's match (Art. 21 GDPR). Email dev.athenateam@gmail.com with your full BattleTag. We stop and delete, and you do not need to give a reason. You can also ask us for the written balancing test behind our legitimate interest.
If you object or ask us to delete your data, we keep a keyed hash of your BattleTag (never the BattleTag itself) on a block list, so that later matches do not add you again. That hash is the only thing we keep. Tell us if you want to be taken off the list.
How long data is kept
- On your computer: until you delete it.
- In the shared database: while a player keeps appearing in uploaded matches we keep that player's pseudonymous history. 24 months after the last appearance we delete the player's id and all per-player rows. You can ask for earlier deletion at any time. Anonymous statistics computed from many players (for example the ranges shown under "Versus your rank") do not identify anyone and are kept.
- Backups: the database is exported weekly to a private store and each export is kept for 30 days. Cloudflare's own point-in-time recovery covers 7 days. Data you delete is gone from backups when they expire.
Your rights
Under the GDPR you have the right to access, correct and delete your personal data, to restrict or object to its processing, to withdraw consent, and to receive your data in a portable format.
- In the app: Settings → Your data shows what the shared database holds from your own uploads and lets you delete it. It does not remove you from matches that other people uploaded: for that, email us your BattleTag (see below).
- Without the app, or if you are a player who appeared in someone else's lobby: email dev.athenateam@gmail.com with your full BattleTag. We compute the pseudonymous id of that BattleTag, tell you what is held, and delete it on request. Because a deletion can only remove data, we delete on request without asking you to prove you own the BattleTag. For a copy of your data we send only what any player in your matches could already see (number of matches and hero shares).
- Local files: delete them yourself from the data folder; nothing else is needed.
- Complaints: you may complain to the data protection authority. For a controller in Sweden that is Integritetsskyddsmyndigheten (IMY).
Children
Turning on match sharing requires you to be at least 13 years old, or the age of digital consent in your country if it is higher. If you are younger, do not turn on sharing.
Changes
When this policy changes in a way that matters, the effective date above changes and the new text is published at the same address. We also show a notice in the app at least 30 days before a material change takes effect.
Contact
dev.athenateam@gmail.com