Its plugin updater seems generally insecure; plugins are downloaded from a third-party website, without encryption or validation. (There is a pleasant warning that "Plugins can contain a virus/malware.") http://bugs.debian.org/640026
As LWN previously noted, Calibre phones home with a UUID on startup. http://lwn.net/Articles/456504/ (disabled in Debian/Ubuntu)