Google Bought 100 Million Spirit Airlines Emails Out of Bankruptcy Court
A $10 million winning bid for a dead airline's internal correspondence, and what it says about where training data comes from once the open web runs dry
Google paid $10 million for the email of a company that no longer exists.
Around 100 million messages. Roughly 500 million Microsoft Teams chats. About 80,000 email accounts, 3.4 million payroll records, employee data going back to 1986, plus Spirit Airlines' pricing models, booking curves, refund histories, and its software code. All of it won at a bankruptcy auction, disclosed in an August 14 court filing and reported on August 17. The runner-up was Mercor, the AI hiring platform, at $7.5 million.
Read the excluded-assets list and the deal changes shape. Spirit's 97.5 million passenger profiles are out. The 52.4 million loyalty members are out. The 740,000 co-branded cardholders are out. Every category of person who had a privacy policy pointed at them got carved from the sale. The people whose mail is in the box are the ones who worked there.
The carve-out is the whole story
Section 363 of the Bankruptcy Code is what governs a sale like this, and 363(b)(1)(B) puts a specific brake on transferring personally identifiable information. The brake trips on a condition worth reading carefully. If the debtor had a privacy policy restricting transfer of that information, and the proposed sale would break it, the sale can only proceed after the court appoints a consumer privacy ombudsman and finds the transfer does not violate consumer privacy interests.
Consumer. That word is doing enormous work.
We watched this machinery run last year on 23andMe, where a court-appointed ombudsman reviewed a proposed sale of genetic data and could not conclude with certainty that it squared with the company's own privacy statements. That review happened because the people in that database were customers, covered by a document the company published and could be held to.
Nobody publishes a privacy policy for employee mail. What employees sign is usually the reverse: an acceptable use policy saying the company owns the account, monitors it, and can do what it likes with the contents. That agreement was written to give the employer control while the company was alive. In Chapter 7 it converts into clean title. The strongest possible statement of "this is ours" turns out to also be the strongest possible statement of "this is sellable."
So the estate did the sensible thing. It carved out the assets that carry a consent problem and sold the ones that don't. Spirit's customers got the protection of a policy they never read. Spirit's dispatchers, revenue analysts, and gate agents got nothing, because there was never a document to protect them.
Two claims about the same data, and they don't quite meet
Here is the part I keep turning over.
A filing by PJT Partners vice president Dylan Friesner, Spirit's investment banker, states the data contains no personally identifiable information. Google's own statement says something different in an important way: "Any data we receive will be rigorously scrubbed of any personally identifiable information by a third party before receipt." Axios reports the data will be deidentified, with the buyer agreeing not to attempt re-identification.
Both statements can be technically true at once, depending on which definition of PII you use. But you cannot need a third-party scrub for something that already contains nothing to scrub. One of those sentences describes the data as it sits today and the other describes it after work has been done to it, and the gap between them is where all the interesting engineering lives.
Deidentifying corporate email is genuinely hard in a way that deidentifying a spreadsheet is not. Strip the From and To headers and the message body still says "per my call with the Fort Lauderdale crew scheduling lead." Strip the names and the writing style survives. Strip the writing style and you have destroyed exactly what makes the corpus valuable. Nobody has published the method here, and no ombudsman was appointed to look at it, because the people being deidentified were staff, not consumers.
Also worth saying plainly: a federal judge still has to approve this deal. It is not final.
Why a dead airline's inbox is worth eight figures
The volume is not the point. Google has more text than it can use.
What it does not have, and what nobody has scraped, is twenty years of a company arguing with itself. A revenue management team explaining in writing why they held a fare through a demand spike. An operations thread reconstructing a bad day at LaGuardia in real time, with the wrong theories still visible before the right one lands. Payroll disputes. Audit findings. The presentation that got killed and the mail explaining why.
Public web text is written to be read by strangers. Internal correspondence is written by people who assume nobody outside the room will ever see it, and that assumption is precisely what makes it useful for training. It contains reasoning with the hedging still attached, decisions with their causes still nearby, and expertise expressed in the shorthand of people who share context.
The software code came along too, which almost nobody covering this has mentioned. Spirit's revenue management systems are the operating logic of a business that competed on price for two decades. That is a working artifact, not a document about one.
And it cost $10 million, which is roughly the price of a small engineering team for a year.
Put this into practice
You cannot stop this transaction. You can find out what your own exposure looks like, and most of these take under an hour.
-
Ask your IT or legal team for the actual retention schedule on email and Teams or Slack. Not the policy document, the configured value. Many companies discover the answer is "forever" because nobody ever set a deletion window and storage got cheap. Everything inside that window is an asset in a liquidation.
-
Search your vendor contracts for "successors and assigns." That clause is how your data travels in a sale. If a SaaS vendor holding your operational data goes under, that sentence determines whether the buyer inherits the obligations along with the bytes. Read it before you need it.
-
If you run a company, split your data map in two. One bucket for consumer PII covered by a published privacy policy, one for internal corpora with no policy attached. Only the first bucket triggers an ombudsman. Knowing which of your assets sit in the second bucket tells you what a bankruptcy trustee would be free to sell, and that is a useful thing to know while you are solvent.
-
Watch the docket if you care about the outcome. Sales under 363 have objection windows, and modifications happen there rather than in press coverage. Spirit's filings are on the Epiq case site, and Axios linked the relevant documents directly.
-
If you buy data for model training, get the provenance chain in writing. Who deidentified it, by what method, under whose review, and what happens if re-identification turns out to be possible. "Scrubbed by a third party" is a sentence, not a control.
Where I'm less sure than I sound
I have not read the docket PDFs. Every figure here comes from reporting that quotes the August 14 filing, mainly Axios, Skift, and Bloomberg Law, and those outlets do not agree with each other. Skift reports 3.4 million payroll records, 80,000 email accounts, and employee data to 1986. Other coverage cited 175,000 employee records and multi-billion-row flight and transaction tables that Skift and Axios do not mention. I could not reconcile those into one number, so I have reported the source alongside each figure rather than picking a favorite.
My reading of 363(b)(1)(B) is a reading, not legal advice. Whether an ombudsman should have been appointed here turns on the exact text of Spirit's privacy policy and on what the estate represented to the court, and I have neither. A bankruptcy lawyer would give you a better answer, and might give you a different one.
Employee mail changing hands in an asset sale is also not new. Enterprise archives transfer in ordinary acquisitions constantly, and usually the buyer wants the business, with the archive coming along as baggage. What is new is that the archive was the point. The buyer here wanted the correspondence itself, priced it, and outbid a competitor for it.
One more thing I want to be honest about: I do not think anyone in this story broke a rule. The estate maximized value for creditors, which is its job. Google bought a lawful asset and said what it intended to do with it. The court will review it. The gap is not misconduct. The gap is that the statute was drafted around a mental model where the sensitive data is the customer list, and that model was correct in 2005.
What to do with this
If you have worked anywhere for more than a few years, some version of this box exists with your writing in it. That was already true. The change is that the box now has a market price and a category of buyer that wants it specifically.
The useful response is not to write differently in your work email, which is both impractical and slightly paranoid. It is to know which of the systems you rely on hold text indefinitely, which of your vendors could pass it along in an insolvency, and which of your own company's data would survive a Chapter 7 as inventory. Those three answers take an afternoon to gather and they will be relevant again, because Spirit will not be the last liquidation with a corpus in it.
The next auction is the one to watch. This one set a price.
Sources: Axios, Skift, Bloomberg Law, Lawfare on the 23andMe bankruptcy, Bloomberg Law on the 23andMe privacy ombudsman, Alston & Bird on data sales under Section 363.