How to Add a PDF to Notion and Track Who Reads It
By Oleh Tsyupa, Founder of PDFTrackr · Published 2026-09-14 · Updated 2026-09-14
7 min readHalf of all validated reading sessions end within 43.2 seconds, and the median page is on screen for 3.02 seconds — which is why "the page was viewed" and "the document was read" are different findings.
If the only thing the workspace page can tell you is that somebody loaded it, you are counting the event least likely to mean anything. Across 3,265 validated sessions from 1,564 first-time visits over 270 documents, the median session lasted 43.2 seconds while the 90th percentile ran to 6.13 minutes — a distribution with a long tail, where the average would describe almost nobody. At page level the same shape holds: a median of 3.02 seconds against a 90th percentile of 37.4, measured over 24,552 distinct page views. The practical consequence for a workspace page is that a load count and a reading record are not two versions of the same number; the first cannot separate the reader who skimmed from the reader who stayed, and the second is the one that changes what you do next.
Based on 3,265 validated sessions from 1,564 first-time visits across 270 documents (PDFTrackr production analytics, 22 Sep 2025 – 25 Aug 2026, last day partial, extracted 26 Aug 2026). Figures are medians, not averages.
If it is quicker to try than to read about, create a free tracked link for the file and paste it into the page where the embed is now — or open the live demo first to see what comes back.
What embedding actually does, and why it stops there
Embedding a file in a page does one thing: it gives the file somewhere to be displayed. The browser loads the framed document as its own separate browsing context, served by whichever origin holds it. Where that origin is a different one from the page doing the framing, the page around it cannot reach inside — that is the browser's same-origin policy rather than a limitation somebody chose, and it runs both ways: cross-origin content cannot read the page that embeds it either. Where a site stores the file and renders it in its own viewer, the browser is no longer the boundary, and what that viewer records becomes the site's own design decision rather than a rule of the web.
The consequence for your question is direct. Across a cross-origin frame, whatever the surrounding page counts, it counts about itself: the scroll position inside the file, the page the reader stopped on, how long page four held them — none of it crosses that boundary, because the framed document is not reporting to the page that framed it. Which leaves one general rule worth holding on to: a reading record for a document comes from whatever serves the document. PDFTrackr is exactly that — a page that serves the PDF and measures it — and that is the whole of the difference here.
That is the same boundary the other channel guides on this site describe from different sides: a chat app, a mail client, a CRM and a text message all measure the message or the page, never the document inside it. The general form is set out at what PDF tracking is, and it is worth reading first if the mechanism is new to you.
Two jobs, and only one of them needs a link
Before changing anything, work out which of these you are doing. The answer decides whether a tracker helps or just adds a step.
| How the file sits in the page | Who reads it | What you can learn about the pages | Worth the extra step? |
|---|---|---|---|
| Uploaded and embedded in the workspace page | Teammates already inside the workspace | Nothing about the pages, where the file is framed from another origin: the framed document does not report to the page around it. Where a workspace serves the file itself, what its own viewer records is its design decision and this page does not establish it | No. For internal reading this is the right answer and a tracker is friction |
| A tracked link in the page, in place of the embed | Anyone with the page, inside the workspace or outside it | Which pages rendered, in what order, for how long, whether a download was clicked, and whether the same visitor came back inside the day — with automated opens classified at session close and excluded from the counts | Yes, when the answer changes what you do next |
| A tracked link behind an email gate | Readers outside your organisation whose names you do not know | The same reading, attached to whatever address the reader typed into the gate | Yes for outbound documents; no for a team wiki, where it is a wall |
| The published workspace page shared as a public URL | Anybody with the URL | Whatever that page's own settings report | It depends what the page's own settings offer; this page does not establish that |
| The PDF downloaded from the page and emailed on | Whoever it reaches next | Nothing. An ordinary copy on somebody's disk reports back to nobody, and no document tracker changes that — one category that does is DRM, which works only because the reader installs a licensed viewer first | No — this is the case every method on this page is trying to avoid |
The verdict, bounded to this table: for a document that leaves the workspace, the tracked link is the pick, because it is the only row that reports what happened inside the file and the only one that separates the machine opens from the human ones before you read anything into a first-day number. Where the plain embed genuinely wins is everything else — a teammate opening a file in a page they are already on needs no link, no gate and no second tab, and that friction is a real cost that a reading record does not always repay.
The steps
One. Upload the PDF and generate a share link for it. The file is served from a link you own, which is the part that makes the reading recordable at all — the same move described at how to host a PDF online and get a link.
Two. Decide the controls before you paste anything. Downloading on or off; an email gate or not; an expiry date or not. A gate is right for a document going to people you cannot name and wrong for a page your own team reads daily, and it is much easier to decide now than to explain later.
Three. Put the link in the page where the embed was, and give it a line of context. A bare URL in a workspace page gets scrolled past; a sentence saying what the document is and why it matters gets clicked. Keep the embed as well if the team reads it in place — nothing stops a page carrying both, and they answer different needs.
Four. Ignore the first few minutes on anything corporate. Mail filters rewrite links in inbound messages and scan the destination before a recipient sees the mail, and that scan looks exactly like a click to anything counting requests. PDFTrackr classifies those automated opens at session close and keeps them out of the counts, and shows what the filter removed rather than quietly shrinking the number.
What to read in the record afterwards
Read sessions, not totals. The number that changes a decision is never how many times a link was opened; it is what one reader did on one visit. A session that covered nine pages over six minutes and a session that rendered page one for eleven seconds both add one to the same counter and mean opposite things.
Read the furthest page, and read it against the length of the document. Where people stop is the only feedback most documents ever get, and it is usually earlier than the author expects — the distribution behind that, and why a median rather than an average is the honest summary of it, is at how long people actually spend reading a PDF.
When Pro becomes the right choice
Everything above is on the plan that costs nothing — per-page reading, the email gate, the exclusion of automated opens, 500MB, 50 files, 50 active share links, twelve months of history, no card. Free is the product rather than a trial, and a workspace with a few documents going out a month never needs to pay us.
Pro becomes the right choice when one shared link stops answering the question. Once the same document goes from the page to a list of named people, bulk personalised links give each one their own link, so the record says which of them read it instead of leaving you to guess. Once a second reading is a signal you would act on, the return-visit alert tells you the hour it happens rather than in the next morning's digest. And once a file in the page gets replaced every quarter, document versioning swaps what sits behind the live link without breaking the link in the page or losing the reading history attached to it. Look at the demo dashboard before deciding.
Frequently asked questions
Can Notion tell me who viewed a PDF I embedded in a page?
We hold no dated fact about what Notion's own analytics include, so this page does not assert one either way — check your workspace's own settings for that. What is settled is the general rule: a reading record for a file comes from whatever serves the file. Where a page frames a document from another origin, the framed document is a separate browsing context and the page around it cannot see inside, so nothing about the pages crosses that boundary. Where a site stores and renders the file itself, the browser is not the boundary and what it records is that site's own design decision. Either way, the way to be certain you get per-page reading is to serve the document from something built to record it, which is what a tracked link does.
Should I replace the embed or add the link beside it?
It depends who reads it. For a document your own team reads inside the workspace, keep the embed — reading in place with no gate and no second tab is better, and a tracking record for colleagues is usually the wrong instinct. For a document that leaves the workspace, use the tracked link, because that is the reader you cannot ask. Nothing stops a page carrying both, and for a page that serves internal reference and outbound sharing at once that is the sensible arrangement.
What does a tracked link record that a page view does not?
Which pages rendered, in what order, how long each was on screen, whether a download was clicked, and whether the same visitor came back inside the day — plus which opens were automated, because mail scanners and link previewers are classified at session close and excluded from the counts rather than counted as readers. The gap matters more than it sounds: across 3,265 validated sessions the median lasted 43.2 seconds while the 90th percentile ran to 6.13 minutes, so a single count collapses two populations that behave nothing alike.
Will the reader know the link is tracked?
Only if you tell them, or if you switch on the email gate, which shows a form saying the address is shared with the sender. Nothing is installed on the reader's device either way — a tracked link opens a web page, it can see that page and nothing else, and closing the tab ends it. Saying plainly in the page that the link reports back costs nothing and generally helps, because a document known to be measured reads as one somebody cares about.
Can I swap the file later without breaking the link in the page?
Yes, on Pro. Document versioning replaces the file behind a live link in place: the URL pasted into your page keeps working, nobody has to be re-sent anything, and the reading history stays attached to the document rather than restarting. On the free plan the straightforward approach is to create a new link for the new file and update the page, which costs one edit and loses nothing except the continuity between the two versions' records.
Sources
- MDN Web Docs — the <iframe> element: “represents a nested browsing context, embedding another HTML page into the current one”, where “each embedded browsing context has its own document” and “script access to a frame's content is subject to the same-origin policy” (accessed 2026-09-14)
- Microsoft — Safe Links in Microsoft Defender for Office 365: URL scanning and rewriting of inbound mail during mail flow, plus time-of-click verification — a machine checks the destination before the reader reaches it. ⚠️ Channel disclosure: learn.microsoft.com did not answer a direct fetch from our network, so this was read through search-engine retrieval of Microsoft's own documentation (accessed 2026-09-14)
- Nielsen Norman Group — How Little Do Users Read? (Jakob Nielsen, May 2008): the finding that a visitor has time to read at most a minority of the words on an average web page. ⚠️ Cited for WEB-PAGE reading and dated deliberately: it is not a measurement of PDFs and this page does not transfer it to one. ⚠️ Channel disclosure: nngroup.com did not answer a direct fetch from our network, so this was read through search-engine retrieval (accessed 2026-09-14)
- Locklizard — PDF Document Tracking (Safeguard logs document opens/views and print requests on a viewer the reader installs first): the source for the document-rights exception in the table's last row. Channel: locklizard.com refuses connections from our network, so this material was read through search retrieval rather than by opening the URL. Already cited, with this date, on /how-to-know-who-opened-your-pdf, /who-downloaded-your-pdf and /track-resume-views. (accessed 2026-07-15)
- PDFTrackr — the free plan's limits, the retention windows and the Pro price, published on the site's own pricing surface (accessed 2026-09-14)
Put a link in the page that answers back
Upload the PDF, paste the tracked link where the embed is, and read which pages your reader actually got to. Free: 50 files, 50 links, 12 months of history, no card.
Create a free tracked linkKeep reading: what PDF tracking is, how to host a PDF online and get a link, and how long people actually spend reading a PDF. Or start with how free PDF tracking works.
Oleh Tsyupa
Founder, PDFTrackr
Has analysed over 3,000 tracked document-viewing sessions on PDFTrackr.