← Back to blog

The Reader's Guide to Digital Privacy: Why Your Book Data Matters

20 February 2026 · 6 min read

Think about the last ten books you read. Now imagine a stranger looking at that list. They'd know something about your political leanings, your health concerns, your relationship status, your ambitions, your fears. A reading history is one of the most intimate data profiles a person can have, and most readers hand it over without a second thought.

Digital privacy for readers isn't a niche concern. It's a fundamental question about who gets to know what you're thinking about.

What your reading data reveals

Every book you add to a digital shelf, every rating you leave, every page you highlight creates a data point. In aggregate, these data points paint a detailed portrait:

  • Political views: Reading books about progressive politics, conservative economics, or radical philosophy signals your ideological leanings.
  • Health concerns: Books about cancer, mental health, addiction, or chronic illness suggest personal or family health situations.
  • Relationship status: Divorce memoirs, dating guides, or books about grief reveal intimate life circumstances.
  • Career ambitions: Books about career changes, entrepreneurship, or specific industries reveal professional plans you might not share publicly.
  • Religious and spiritual exploration: What you read about faith, doubt, or spiritual practice is deeply personal.

This data is valuable to advertisers, data brokers, and potentially to employers, insurers, and governments. It's not hypothetical: reading data has been subpoenaed in legal cases, and Amazon's data practices have been the subject of regulatory scrutiny in multiple jurisdictions.

The Goodreads problem

Goodreads is owned by Amazon, the world's largest bookseller. When you use Goodreads, your reading data feeds directly into Amazon's advertising and recommendation infrastructure. Your reading habits inform what ads you see, what products are suggested, and how your consumer profile is constructed across the entire Amazon ecosystem.

Goodreads profiles are public by default. Your reviews, your ratings, your shelves, even your "want to read" list, are visible to anyone unless you manually change your privacy settings. Many users don't realise this, and the privacy settings themselves are limited: you can make your profile private, but you can't control how Amazon uses your data internally.

This isn't a conspiracy theory. It's the business model. When a product is free, the product is your data. Goodreads has never charged users a fee because the data is more valuable than any subscription would be.

Why GDPR matters for readers

The EU's General Data Protection Regulation gives European readers specific, enforceable rights over their personal data:

  • Right to access: You can request a complete copy of all data a company holds about you.
  • Right to erasure: You can request that a company delete your data entirely.
  • Right to portability: You can request your data in a machine-readable format and take it elsewhere.
  • Data minimisation: Companies can only collect data that's necessary for the service they provide.
  • Consent requirements: Companies must obtain clear, informed consent before processing your personal data.

For readers, these rights mean something concrete. A reading tracker that's GDPR-compliant can't collect more data than it needs, can't share your data without your explicit consent, and must delete your data if you ask. A reading tracker that isn't GDPR-compliant, or that's based in a jurisdiction without equivalent protections, makes no such guarantees.

How to protect your reading privacy

You don't need to go off-grid. A few practical steps make a significant difference:

  • Check your privacy settings. On whatever reading platform you use, audit your profile visibility. Make your shelves and reviews private if you don't want them public. This sounds obvious, but most people never do it.
  • Choose platforms that respect privacy by design. Look for reading trackers that are private by default, that host data in the EU or in privacy-respecting jurisdictions, and that make money from subscriptions rather than data sales. The business model tells you everything about the incentives.
  • Use your data rights. If you're in the EU, exercise your GDPR rights. Request your data from platforms you've used. See what they've collected. You might be surprised.
  • Be thoughtful about what you share publicly. There's nothing wrong with sharing book reviews, but do it intentionally. A public review is a permanent record of your intellectual life, and you should choose what's in it.
  • Keep a local backup. Whatever platform you use, export your data regularly. A CSV file on your own computer is data that nobody else controls.

The bigger picture

Libraries have understood this for centuries. Librarian ethics include a fierce commitment to patron privacy: the books you borrow are nobody's business. This principle exists because reading is an act of intellectual exploration, and exploration requires safety. If you know someone is watching what you read, you read differently. You self-censor. You avoid the controversial, the embarrassing, the vulnerable.

Digital reading trackers should uphold the same principle. Your reading life is yours. The data it generates belongs to you. And the platforms you trust with that data should treat it with the same respect a librarian would: as a confidence, not a commodity.

The next time you add a book to your digital shelf, take a moment to consider where that data goes and who benefits from it. Your reading history is a map of your mind. It deserves better than being someone else's product.

Ready to start tracking?

Join readers who track, discover, and share their reading life with Nocturn. Free forever, no credit card needed.

Create free account