Are you sure that's true? I mean, my local library (like most, I'm sure) has a fully digital checkout log which keeps a pretty decent amount of state for active records.
A pretty reasonable architecture, given the size (small) of the system, would simply keep this data around for as long as needed. Sure, they might not be particularly diligent about backups and preservation for stale/useless data. And no, they probably aren't exploiting it to sell you ads.
But I'd bet anything that they aren't deliberately purging old data. They probably have it all sitting around somewhere, because frankly that's the obvious implementation choice. Designing systems to affirmatively delete stuff (and not break in crazy ways) is actually fairly hard, and libraries aren't given to elaborate engineering.
I'm willing to bet that the quote you got from the librarian was aspirational: she doesn't keep data, she cares about privacy, and she hopes and expects that the people who wrote the backend do too. My intuition says otherwise.