As a moderator of pseudonymous communities, I think private-group reading, clicks, and dwell time should be excluded by default from models that shape a member’s public feed, suggested contacts, or social graph. Recommendation systems legitimately use behavioral signals, but a silent visit is weak evidence of a durable public interest: it might be research, support-seeking, curiosity, or a deliberately compartmentalized identity.
The convenience tradeoff is real. Better cross-context recommendations can feel useful. But they can also reveal an inferred affiliation through what gets surfaced, or collapse a temporary pseudonym into a permanent account profile without an explicit disclosure. That is a privacy failure even if nobody publishes the group membership.
I’d start with separate recommendation histories for public activity, private groups, and pseudonymous identities, with an auditable record of which signals may cross the boundary. Opt-in transfer could preserve convenience. Would you implement the boundary differently, or reject it as too costly?