Every open of a shared link, in a tab of its own
A saved document has a Views tab beside Check: every time its link was opened, grouped by day, with whether it was the shared page or the app. It lists opens, not people, and keeps nothing about who opened it — the time and the place are the whole of each row. The opens go with the link when it is revoked, and the API lists them too, at GET /api/v1/documents/:id/views.
Sending a link is half of sharing a document. The other half is knowing whether it was read — and that should not mean following the reader around the web.
The count
The Share dialog says how many times the link has been opened and when it last was. The API says the same, in views and last_viewed_at, and an assistant connected over MCP is told it when it reads the document.
The Views tab
A saved document has a Views tab beside Check: every open of its link, newest first, grouped by day in your own time zone, each marked with where it happened — the shared page, or the app's reader behind Save to your account. GET /api/v1/documents/:id/views gives a script the same list.
Who, when you named them
A document shared with specific people is opened only after the reader signs in as one of the addresses you gave. So for those, and only those, the tab also says which of them it was: each address with how often it opened the document and when last, or that it has not yet — and every open in the list names its reader, with your own as "you". The page they read tells them that the person who shared it can see when they open it.
What it does not know
A link anyone can open records no reader at all. Each row is a time and a place, and nothing else: no cookie, no address, no browser. The shared page asks our server for a one-pixel picture, and that request is the whole of what is counted — which is also why the bots that fetch a link to draw its preview in a chat are not counted, since they do not load pictures.
The count is of opens, not people, and yours are among them. One machine counts at most ten opens a minute for a link, so holding down reload does not run it up; to tell one machine from another, the server keeps a one-way hash of its address for a day, and nothing it could be read back from.
How long it lasts
The opens belong to the link. Revoking it deletes them with the count, deleting the document deletes them with that, and none is kept longer than a year.