SReader Blog
Run a Personal Privacy Audit on Every Reading App You Use
Four at-home tests, one scorecard: audit any reading or note app for offline behavior, network traffic, permissions, and where your data lives.
Run a Reading App Privacy Audit on Every App You Own
Four at-home tests, one scored sheet. It works on every reading and note app you already use, and it stays useful even if you never switch apps.
Your reading app knows what you highlighted last month. It knows which chapter made you quit, which terms you looked up, and how long you sat with page 214 before closing the book. Highlights can reveal beliefs and health concerns. In-app searches can reveal intent, including symptom and legal lookups. Library contents signal religion, politics, and profession. Reading times expose routines and stress. Each signal looks small on its own. Together they form a portrait you never agreed to sit for.
That is not a reason to panic, and it is not a character flaw if you never thought about it. Reading apps run quietly, their network activity is invisible by default, and nobody hands you a receipt for what leaves the device. So make one. A reading app privacy audit gives you four tests you can run at home, a one-page scorecard, and a defensible score for every reading and note app you own.
The goal is not to talk you out of cloud sync, which has genuine benefits. The goal is to see the trail clearly enough to decide what you accept. The basics need nothing more than airplane mode and your device's settings screens.
The evidence: over 100 server requests from one reading session
Before the method, one data point that shows what is at stake. An independent traffic capture of the Kindle app recorded a deliberately boring session: open the app, read a book, flip a few pages, close it. "Opening the app, reading a book, flipping through a few pages, then closing the book sends over 100 requests to Amazon servers."

Each page read transmitted a record carrying the schema name kindle_positions_consumed_v2. The record held a timestamp, the exact start and end character positions in the book, and whether the page was text or images. Sessions also produced navigation summaries, reader_in_book_navigation_v2, with page-turn counts, navigation mode, and start and end locations. Selections traveled further than Amazon: highlighting or tapping any word sent the selected text to Bing Translate and Wikipedia as well. The app also transmitted country of residence, attempted a local-network IP lookup, and sent device make, model, and software version, Goodreads account details, and device orientation.
One finding matters more than the rest for this audit: offline is not untracked. In the capture's words, "A number of these records are created and stored locally, then uploaded (note the sequence_number field). Even if a person is offline while reading, this data is stored and sent when reconnected."
Keep that reconnect trap in mind. Several tests below look for exactly this pattern.
How the audit works: four tests, one sheet
A reading app privacy audit has four parts: an offline test, a network test, a permissions and account review, and a data-residency score. Each part maps to something you can verify yourself rather than take on trust. That is the credibility spine of the whole exercise: apps may market on-device processing while still phoning home, so score observed behavior, never marketing claims.
The audit is tool-agnostic by design. Run it against ebook apps, PDF readers, read-later apps, and note apps alike. Your sheet holds one row per app, and each test feeds one dimension of the final score: where your reading data lives, and what leaves the device.
Test 1: the airplane-mode audit
Toggle airplane mode, then exercise the whole app. Open a book, turn pages, highlight, search, set bookmarks, adjust settings. For each feature, record one of three outcomes: it works fully offline, it breaks, or it completes but seems to queue for later. Five minutes per app.

Interpret with care. "It worked in airplane mode" does not prove nothing was collected, because the Kindle capture showed records created offline and uploaded on reconnect. A feature that works offline can still be logging. What the offline test gives you instead is a shortlist for Test 2: anything that breaks, and especially anything that seems to queue for later, belongs on it.
The test also shows you what an offline ebook reader with no tracking looks like in practice. Settings, bookmarks, and reading progress respond normally with the network gone. Nothing queues. No account stands between you and page one.
Test 2: watch the wire
Plenty of people type "which apps track my reading habits" into a search box and get opinion pieces back. The reliable answer requires watching traffic leave the device while you read. The EFF's guide to intercepting your own Android app traffic describes the standard home setup: a test device running the app, connected through a wireless access point running mitmproxy or Burp Suite to record what passes. Because most traffic is HTTPS, interception requires overriding Java's TrustManager, commonly done with the Frida instrumentation toolkit. A fully mobile, single-device version requires a rooted Android phone.

That is a real technical barrier, and you should be honest about whether it is yours. The EFF's reason for clearing it anyway is simple: "An app asking for permission to your location may only use it to send it to your friends, or it may be tracking your every move. Without knowing exactly what traffic is being sent, you'd never know."
During a plain reading session, log three things: the request count, the destination domains (vendor servers, translation and wiki lookups), and any payload contents you can read, such as timestamps and character positions. Then compare the log against your airplane-mode sheet.
If the proxy setup is beyond you today, use the fallback: pair Test 1 with a documentation review. Read what the developer claims the app does and does not do, and expect precise, verifiable statements. SReader offers a decent model of the genre: "PDF import extracts text; it does not preserve the original page layout, perform OCR, or convert PDF files to EPUB." You can check that claim in five minutes, which is the point. A page that says only "we respect your privacy" fails this review.
Test 3: app permissions, account demands, and your reading data
The third test is a checklist you run in your device's settings. List every permission each app requests, at install and during use. A reader whose only job is opening local files needs very few, so treat any permission that does not map to a reading feature as a question to investigate. Then map the account spectrum: none, optional, or mandatory. Try to open the app and read without signing in, and record every core feature gated behind an account, along with what signing in enables, from sync to telemetry to social features.
The EFF's caution applies here too: a permission request alone cannot tell you how your data is used. Only Test 2 settles it. Both permission minimality and account demands feed the rubric directly. If you want the longer version of why account walls exist, see Why Reading Apps Want an Account Before You Read Page One.
Score it: where reading data lives and what leaves
Turn your results into a score. Five dimensions, one row per app:
- Account: none, optional, or mandatory
- Offline: core reading works fully offline or not
- Traffic: sync and telemetry observed while reading
- Permissions: minimal or padded
- Controls: export and delete, present and functional
Score each dimension from what you observed in Tests 1 through 3, then read the row as a tier:
Tier | What it means |
|---|---|
Green | Local-first, no account. Reading data stays on your device. |
Yellow | Optional account, selective sync. You control what crosses the wire. |
Red | Mandatory cloud, telemetry by default. Assume reading behavior is logged server-side. |
A worked green-tier example: SReader's positioning is "No account · No ads · No feed · Your library stays on your device," with settings, bookmarks, and reading progress kept on-device across iPhone, iPad, Mac, and Android. Each claim is checkable against the tests: airplane mode changes nothing, no account wall exists, and the permissions list is short for a reason.
The rule of thumb for the whole sheet: score what you saw the app do, never what its marketing page says it does.
A red score is not a life sentence
A poor result has answers that do not require abandoning your library. Kindle users have two in-settings levers, documented in Kindle privacy walkthroughs. Disabling Whispersync (Settings > Account > Whispersync for Books) stops reading position and highlight data syncing to Amazon's servers. The research opt-out under All Settings > Device Options > Advanced Options > Privacy limits some data uses, though it does not stop all collection tied to the account. Exporting highlights and notes keeps a local copy you control, and we have a guide to backing up highlights from any reader app if you want one.
Kobo's data-sharing toggle hides in a different place on each platform: on the eReader under More > Settings > Energy saving and privacy, where you uncheck "Automatically share data about the features you use"; in the iOS app under More > Settings, labeled "Help Improve our App"; in the Android app under the Profile icon. Two caveats from Kobo's own documentation: the toggle affects only that single device, so repeat it per device, and preferences reset after a device reset or sign-out, so re-check afterward.
Then the universal mitigations, available in any app ecosystem: read in airplane mode when you can, import local files instead of cloud catalogs, revoke permissions you never use, and build an offline library of what matters most.
Be honest about the ceiling here. These levers shrink the trail. They do not change where the data lives, so a mandatory-cloud app stays red-tier on data residency no matter how carefully you tune it.
Read your results, then re-audit
Interpretation is personal. Green means reading data stays on your device. Yellow means you control what syncs, and that control is worth using deliberately. Red means you should assume reading behavior is logged server-side, which may still be an acceptable trade for sync, family libraries, or recommendations. The audit supplies the facts; your risk tolerance assigns the weight.
Re-run the audit after major app updates, device resets, and sign-outs. The Kobo case shows why: settings can silently revert. For a re-check, the airplane-mode test is the natural starting point: toggle it on, exercise the app, and note anything that now behaves differently.
Finally, the audit stands on its own. Knowing which apps track your reading habits is worth an afternoon even if you never switch a single app. If you want a green-tier comparison point for your next run, Try SReader, local-first focus reading for iPhone, iPad, Mac, and Android. And if a red score does push you toward a change, run your candidates through A Ten-Point Checklist Before You Switch Reading Apps before you commit.
Your highlights, your searches, your reading times: they belong on your device.