Is It Ethical to Track a Document You Sent?
Most people ask this question about four minutes after they first see a notification saying somebody opened their proposal. The feeling is not guilt exactly. It is the small unpleasant lurch of realising you now know something the other person did not choose to tell you.
That lurch is worth paying attention to rather than arguing away. It is the difference between two activities that share a name.
Two different things are both called tracking
The first is measuring an artefact you made. You wrote a document, you sent it to a named person for a stated purpose, and you would like to know whether the thing you spent nine hours on was read. The subject of the measurement is the document.
The second is building a picture of a person. Following them across sites, joining what you see to data bought from somebody else, inferring things they did not disclose, keeping the file after the reason for it has gone. The subject of the measurement is the human being.
The first is ordinary professional feedback and has existed in some form since couriers came back and reported that the letter was handed over. The second is surveillance. They are separated by a line, and almost every argument about whether "document tracking is ethical" is really an argument about where that line sits.
Test 1 — Did you send it to them?
This is the load-bearing one and it does more work than any other. There is an enormous moral difference between instrumenting a document you addressed to somebody and instrumenting a person who wandered past.
When you send a proposal to a named client, you have both entered a mutual transaction with an obvious shape: you are asking for their attention and their answer. Knowing whether the attention arrived is inside that transaction. It is the same category of knowledge as seeing that they turned up to the meeting.
The moment you are watching somebody who never asked you for anything, none of that applies and no amount of visible notice repairs it.
Test 2 — Can they see that it is happening?
Secrecy is what turns measurement into surveillance, and it is the only ingredient that reliably does. Tracking somebody was told about is analytics. Tracking nobody was told about is surveillance, whatever the data is.
The practical version of this test is brutal and useful: would you be comfortable if the person you sent it to could see exactly what you can see? If the answer is no, the problem is not that they might find out. The problem is what you are collecting.
Every document shared through Quixli carries a fixed notice at the foot of the reader’s screen that says, in those words, “The author of this document can see view statistics.” It is there from the first paint, on every share type, and it is not dismissible. It deliberately does not enumerate the fields — a wall of specifics reads as a legal shield and gets ignored — but nobody reading a document sent this way is under the impression that nothing is being counted.
Test 3 — Does it change what you do to them, or only when you do it?
This is the test almost nobody applies, and it catches the cases the first two miss.
Read data used well changes your timing. You call on the day somebody is thinking about you rather than on the day your calendar reminder fires. You stop chasing a proposal that was never opened and fix the email instead. Nothing about the client’s treatment changes; only the clock does.
Read data used badly changes your leverage. You price differently because you can see they came back four times. You open with a line designed to make them feel watched. You treat "read it twice and went quiet" as a moral failing on their part rather than as information about your document.
The first is scheduling. The second is manipulation dressed as insight, and it is on the wrong side of the line even though the data is identical.
So where is the line, concretely?
Things that stay comfortably inside it:
- Knowing that a document you sent to a named person was opened, and when
- Knowing how long each visit lasted, and whether they came back
- Knowing that a second, unfamiliar reader appeared — which usually means it went internal
- Using any of the above to decide when to follow up and what to lead with
- Turning the whole thing off for a document where it would be inappropriate
Things that are on the far side of it, and the reason is the same each time:
- Joining read data to anything bought from a third party. The moment you enrich a visit with data the reader never gave you, the subject of the measurement stops being your document.
- Following the same person across documents you did not send them. That is a profile, not feedback.
- Telling the reader things about themselves they did not disclose. “I see you’re in Hamburg” is the single fastest way to convert a warm prospect into somebody who never replies again. It is also, quite often, wrong.
- Using the numbers as evidence in a dispute with the person they describe. They were not collected for that and they are not good enough for it.
The genuinely uncomfortable case
Here is the one that does not resolve cleanly, and any article that tells you it does is selling something.
You send a proposal to one person. They forward it internally. Now three people you have never contacted are reading a document that is counting their visits, and none of them agreed to anything with you. The notice is on their screen — but they did not choose to be in the room.
There is no version of tracked links where this does not happen, because forwarding is the normal path work takes through a company. The honest position is not to pretend the notice fixes it. It is to be careful about what you conclude. A second reader is a signal that the document reached the people who decide, which is the most useful thing you will learn all week; it is not an invitation to work out who they are. What a forwarded link can and cannot tell you goes through what that data actually supports.
What we deliberately do not do, and why it matters here
A vendor’s ethics are best judged by the features it declined to build, so here are ours. Quixli does not record where in a document somebody read — there is no scroll depth and no per-section heatmap. It does not record the referrer, so the document a reader arrived from is not stored. It does not fingerprint browsers: the only thing linking two visits is a random identifier in a first-party cookie the reader can clear at any time. It does not send a reader’s address to any external service to look up a city; that lookup happens against a local database. And it does not buy, sell or enrich reader data with anything from anybody.
The full inventory — both columns, what is collected and what is not — is in what a tracked link actually collects. What Quixli measures sets out the same boundaries on the product side.
The test that survives contact with reality
Forget the framework for a second. The working version is this: would you be willing to say out loud, to the person you sent it to, that you can see when they open it?
If yes, you are doing analytics and you should stop worrying. If no, do not fix it by hiding it better. Fix it by collecting less, or by not collecting at all.
That leaves the obvious follow-on question, which is whether you should actually say it — and to whom, and when. Should you tell a client you can see they opened it answers it, and the answer is not the one most people expect.