Privacy policy
A plain-language account of what OverAnalyzer stores, why it stores it, and how you can remove it.
Last updated 24 August 2026
What this covers
This policy covers the OverAnalyzer web app and its optional Windows capture companion. The companion captures only when you press its hotkey; it is never continuous. It does not read the game process or draw an in-game overlay.
What we collect
- Your email address and sign-in identity, handled by Supabase when hosted authentication is enabled. If you use Google sign-in, OverAnalyzer receives your email address, not your Google password.
- The in-game name you enter during onboarding so the service can identify your row on a scoreboard.
- Two full game frames when you submit a Game Report manually or through the companion. The server uses them only in request memory to select the Summary and locate the Teams regions. Full-frame pixels are never written to the database, object storage, job queue, or logs.
- The located Summary region and each team leaderboard with a bounded margin, plus the match statistics, OCR results, and corrections extracted from them. A leaderboard includes the in-game names, heroes, and statistics of other players in the lobby.
- If you pair the optional companion, a device-key record. The plaintext key is shown once; the backend stores a SHA-256 hash rather than the usable key.
- Optional, scrubbed error reports if the deployment has error reporting configured. This is not enabled by default; the reporting code removes request bodies, tokens, user data, and exception messages before sending an event.
How we use it
- To process your screenshots, show your match history, and calculate the analytics you request.
- To retain only the located Game Report regions as the source of truth so a match can be re-processed when OCR improves.
- To authenticate your account, operate paired devices, prevent abuse, and fix service errors.
What we do not do
- No advertising or ad network is part of the app.
- We do not sell your screenshots, match history, or extracted statistics.
- OverAnalyzer does not connect to your Battle.net account, read game memory, hook the game process, inject code, or render an in-game overlay.
Other players in your screenshots
Your scoreboard capture may contain other players' in-game names, heroes, and match statistics. That information is retained as part of your match record and is not linked by OverAnalyzer to a real-world identity. Do not upload screenshots you are not allowed to use, and do not use the service to harass other players.
Account match data is intended to be account-scoped. The public demo is a separate read-only showcase and may contain seeded fixture data with real in-game names; do not treat the demo as a private account.
Storage and retention
The app supports local filesystem storage for development or self-hosting and private S3-compatible object storage, including Cloudflare R2, for a hosted deployment. Match data is stored in SQLite or Postgres, depending on deployment configuration. Only the located Game Report regions are retained; the two full source frames are discarded in request memory. Retained regions remain until you delete the match or account, report and remove the capture, or the deployment removes them under its own retention rules. Requests in a hosted deployment are served over HTTPS.
Reporting and removing a capture
If a retained image contains unrelated, private, or prohibited content, open that match's Details tab and choose Report and remove. After you confirm and describe the issue, OverAnalyzer keeps the text report for follow-up and immediately removes the match and every retained image from active storage. If storage cannot confirm deletion, the report is still delivered to the service owner and the app tells you removal needs follow-up.
To request removal of information in another account's private archive, sign in and use the feedback form. Do not attach or re-upload the content; describe the Game Report, gamertag, and reason for the request instead.
Deleting your data
Account owners can delete their account from Settings. The deletion removes the account's matches, raw screenshots, OCR history, corrections, rank calibrations, player and group records, and paired device keys from the configured database and object storage. It is permanent; keep your own copies of anything you want to preserve.
To stop a still-valid sign-in session from silently recreating a deleted account, the service retains a one-way hash of the hosted sign-in subject. It does not retain the subject itself or the account email in that record. Deleting OverAnalyzer data does not delete the separate identity-provider account managed by Supabase. Copies in provider backups or object-storage versions may remain until the deployment's documented retention periods expire, but must not be restored to the active service after deletion.
Your data is yours.
From Settings, you can permanently delete your account and the matches, screenshots, corrections, rank calibrations, player/group records, and paired device keys stored under it. Deletion cannot be undone.