Should You Tell People You're Tracking a Document?

By Oleh Tsyupa, Founder of PDFTrackr · Published 2026-08-28 · Updated 2026-08-28

8 min read

The median recorded reading session in our own production data runs 43.2 seconds, and nine sessions in ten are shorter than 6.13 minutes — that is the scale of the thing you would be disclosing.

Disclosure conversations go badly when both sides imagine surveillance. What a tracked link holds is a short, shallow record of one document: when it was opened, which pages rendered, roughly how long each held attention, and the approximate country and kind of device it was read on. Saying that plainly is less alarming than leaving it to the imagination.

Based on 3,265 validated sessions from 1,564 first-time visits across 270 documents (PDFTrackr production analytics, 22 Sep 2025 – 25 Aug 2026, last day partial, extracted 26 Aug 2026). Figures are medians, not averages.

If you want to see exactly what a reader's record looks like before you decide how to describe it, create a free tracked link and open your own document through it — 50 files, 50 links, 12 months of history, no card — or look at the live demo on sample data first. The rest of this page is what to say about it.

What does your reader actually see when they open a tracked link?

A cookie notice, and nothing about reading. When someone opens a PDFTrackr share link the document loads in a page we serve, and a bar at its foot carries one sentence:

“We use cookies to measure site usage.”— the consent bar on every PDFTrackr share link, read 2026-08-28

Beside it are links to our privacy and cookie policies, and Accept and Decline buttons. That is the whole of the notice.

The viewer does say three other things to a recipient, and it is worth knowing what they are before you write your own sentence. A link that asks for an address carries one line under the box: “Your email is shared with the document's sender.” A link sent from a free account shows a dismissible card once during the read, carrying “See who finishes yours. Free →”, which advertises the product to your reader rather than describing what you will see. And every gate card is footed “Protected by VeoDocs”. None of the three says that the sender is shown which pages were read.

Read that sentence the way a recipient would. It tells them a website is measuring usage, which is what almost every website they opened today told them. It does not tell them that a specific person will be shown which pages they reached and how long they spent on each one. Those are different disclosures, and only the first is being made. The second is described in the privacy policy, where a reader who goes looking finds that we identify a visit without cookies — the IP address and browser user-agent combined into a one-way, daily-rotating hash — and that the IP itself is used only to look up an approximate country and is then discarded.

So the honest position is this: the product hides nothing, and it does not do your telling for you either. A recipient who reads a privacy policy can find out; one who does not will not be told. If you want the person on the other end to know before they open it — and the rest of this page argues you do — the sentence has to come from you.

Where does the professional line sit? Between hidden software and a link you sent

Between something the recipient could not have known about and something they chose to open. The clearest statement of it comes from a bar association rather than a vendor. In January 2018 the Illinois State Bar Association issued Professional Conduct Advisory Opinion 18-01, on tracking software in emails and other electronic communications. Its holding, in our own words rather than dressed up as a quotation from theirs: a lawyer may not use such software in communications with clients or other lawyers without first obtaining each recipient's informed consent. Bloomberg Law reported it under the headline that lawyers cannot secretly track emails.

The carve-out is the part worth carrying into ordinary business correspondence: it does not extend to the visible kind — an Outlook read receipt or delivery notification, which the recipient is shown and can decline, sits outside the prohibition. The distinction is not the measurement. It is whether the person on the other end had any way of knowing.

That is the line an email tracking pixel fails and a tracked link can pass. A pixel is a transparent image in the message body that loads as the mail client renders it, with no action by the recipient and no notice to them — what a PDF tracking pixel is and why it mostly does not work goes through the mechanism. A tracked link is the opposite shape: the recipient sees a link, decides whether to click, and lands on something visibly a hosted viewer rather than a file on their disk. It can pass the line; it does not pass automatically, because clicking a link is not the same as being told what the sender will see. One sentence from you closes that gap.

What are you actually disclosing? Six things, and none of them is the reader

A document, a moment, a depth, a duration, a country and a device — plus, if you asked for one, an address the reader typed in. A reading record says this document was opened at this time, from roughly this country and on this kind of machine, these pages rendered, each held attention for about this long, and the reader stopped here. The country and the device are the two that come nearest a person, and both are coarse: a country rather than a place, and mobile, tablet or desktop rather than a machine you could pick out. It does not identify a person on its own. The definitional groundwork is at what PDF tracking is; what matters for a disclosure is that the honest description is short. Every item is on the free plan — page-level reading data is the product here, not the upsell — so nothing above depends on what you pay.

One item deserves a sentence of its own, because it changes what the number means. Automated opens — corporate mail-security scanners that follow every link in an inbound message, and link previewers that fetch a URL to build a thumbnail — are classified and excluded from the counts. That matters to a disclosure in a way that is easy to miss: without it, the first “view” you tell your reader about is frequently not theirs at all. In our own production data 14.2% of recorded views — roughly one in seven — registered no page at all, and whether PDF view counts are real is where that dataset and its method live. Telling someone you can see they read it, on the strength of a scanner's open, is a worse outcome than not telling them anything.

There is a regulatory floor under this and it points the same way. Where personal data are collected from the person themselves, Article 13 of the General Data Protection Regulation requires that they be told, at the time of collection, who is processing it and for what purposes. Whether a given reading record is personal data in a given jurisdiction is a question for a lawyer, not for this page. The practical reading holds either way: there is no version of this where the recipient finding out later goes better for you than the recipient being told first.

Four ways to send a document, and what each lets the reader know

Read the second column. It is the one the ethics opinions turn on, and it separates the methods far more sharply than what the sender learns.

Four delivery methods, and what each one lets the recipient know about being measured. Outlook read-receipt behaviour from Microsoft's own documentation, accessed 2026-07-29; PDFTrackr's viewer notice from its own share viewer, read 2026-08-28.
How the document reaches themCan the reader tell measurement is happening?What the sender learnsWhat the reader can refuse
PDFTrackr tracked linkPartly — they open a hosted viewer that shows a cookie notice and links to a privacy policy, but no notice says the sender sees per-page readingThat it was opened, which pages rendered, how long each held attention, and the reader's approximate country and kind of device; automated opens from scanners and previewers are classified and excluded from the countsOpening the link at all
Tracking pixel inside an emailNo — the image is invisible and loads as the message rendersThat the message was opened, and little beyond itBlocking remote images, which many clients now do by default
Outlook read receiptYes — the request is shown to the recipient before anything is sent backThat the message was marked read, if the recipient agrees to itDeclining the receipt, which the recipient is offered
Plain PDF as an email attachmentThere is nothing to tell them aboutNothing after you press sendNothing — there is nothing to refuse

The middle two rows are the interesting pair: they measure almost the same thing and sit on opposite sides of the line. A pixel and a read receipt both report that a message was opened. One asks and one does not, and that difference is what the Illinois opinion turns on. A tracked link starts on the read receipt's side — opening it is a deliberate act — and then leaves a gap only the sender can close.

How do you say it in one line?

Name the mechanism, name what you will see, and stop. The failure mode is not bluntness but vagueness: a reader told “we use analytics” fills the gap with something worse than the truth. Three versions, by situation:

Sending a proposal or a deck. I've sent this as a link rather than an attachment so I can tell whether it arrived and which sections you spent time on — that way I follow up on the right thing rather than chasing you. This version costs nothing: the reason is one the recipient recognises.

Sending a contract or anything with a signature at the end. The link records that it was opened and how far through you got. Say the word and I'll send the file itself instead. Offering the plain file turns a notification into a choice, and it is rarely taken up.

Sending to a team — a handbook, a policy, a training document. This link shows me who has opened it and how far they read, so I can stop chasing the people who already have. Internal reading is where saying nothing is most likely to be discovered and resented, and where the stated reason is most obviously true.

One thing not to write, in any of the three: a promise about what you cannot see. Every version of that sentence we have tried is either vague enough to be worthless or specific enough to be a claim the recipient cannot check. Describe what the record holds, and let the smallness of it do the reassuring.

If you have never seen one of these records from the sender's side, fix that before writing the sentence. Open the demo dashboard on sample data, or send yourself a tracked link and read your own session back. Describing what you have seen is the difference between a sentence that reassures and one that hedges.

Frequently asked questions

Do I have to tell someone I'm tracking a document I sent them?

Ethically, tell them; legally, ask a lawyer about your jurisdiction. The Illinois State Bar Association's Professional Conduct Advisory Opinion 18-01 (January 2018) holds that a lawyer may not use tracking software in communications with clients or other lawyers without each recipient's informed consent, and does not extend that to the visible kind — a read receipt the recipient is shown and can decline. That distinction travels outside the legal profession: the objection is almost never to being measured, it is to not having been told.

What exactly does a tracked link record about the reader?

That the document was opened, which pages rendered, how long each page held attention, where the reader stopped, an approximate country, the kind of device it was read on — mobile, tablet or desktop — and, if downloads are left on, whether a copy was taken. Automated opens, from corporate mail-security scanners and link previewers, are classified and excluded from the counts, so the record describes human reading rather than a machine's. It does not name a person on its own: an address appears only where a reader typed one into an email gate. The country is derived from the IP address, which is then discarded, and the visit is identified without cookies.

Does PDFTrackr tell my recipient that I can see their reading?

No, and it is worth being exact about it. The notice a reader sees on a PDFTrackr share link is a cookie bar reading "We use cookies to measure site usage.", with links to our privacy policy and cookie policy. That is a disclosure about site measurement, not a statement that the sender will be shown which pages they read; the fuller description lives in the privacy policy. If you want your recipient to know before they open the document, the sentence has to come from you.

Is document tracking the same as an email tracking pixel?

No — they differ on exactly the point the ethics opinions care about. A pixel is an invisible image inside the message body that loads as the mail client renders it, with no action by the recipient and no notice to them. A tracked link is one the recipient decides whether to click, landing on a page visibly a hosted viewer rather than a file on their disk. That makes the link the more disclosable of the two — but clicking is not the same as being told what the sender will see, which is the gap a one-line notice closes.

What is a one-line disclosure I can copy?

"I've sent this as a link rather than an attachment so I can tell whether it arrived and which sections you spent time on — say the word and I'll send the file itself instead." It names the mechanism, names what you will see, gives a reason the recipient benefits from, and offers the alternative. Avoid promising what you cannot see: a reassurance a recipient cannot check is worth less than a plain description of the record.

Sources

  1. Illinois State Bar Association — Professional Conduct Advisory Opinion 18-01, use of tracking software in emails or other electronic communications (informed consent required; visible read and delivery receipts excluded) (accessed 2026-08-28)
  2. Bloomberg Law — Lawyers Can't Secretly Track Emails, Illinois Bar Says (reporting on Opinion 18-01) (accessed 2026-08-28)
  3. Microsoft Support — Add and request read receipts and delivery notifications in Outlook (recipient can decline; no way to force a receipt) (accessed 2026-07-29)
  4. EUR-Lex — Regulation (EU) 2016/679 (GDPR), Article 13: information to be provided where personal data are collected from the data subject (accessed 2026-08-28)
  5. PDFTrackr — Privacy Policy (our own; cookieless viewer identification) (accessed 2026-08-28)

See the record before you describe it

Send yourself a tracked link and read your own reading session end to end. Free: 50 files, 50 links, 12 months of history, no card.

Create a free tracked link

Keep reading: what PDF tracking is, what a PDF tracking pixel is, whether PDF view counts are real, and how free PDF tracking works.

Oleh Tsyupa

Founder, PDFTrackr

Has analysed over 3,000 tracked document-viewing sessions on PDFTrackr.