What I learned:
The sale everyone is calling a customer-data auction explicitly excludes the customer data - Google won the Spirit Aviation Holdings bankruptcy auction at $10 million, outbidding AI training-data firm Mercor's $7.5 million, per Bloomberg Law and Axios. The package runs to roughly 100 million emails, 500 million Microsoft Teams and collaboration records, 17 million OneDrive files, 30 million lines of code and more than 175,000 employee records, per Aviation Today. What is carved out: the 97.5 million passengers, the 52.4 million loyalty members, the 740,000 co-branded cardholders. The asset is the employees' work product, not the customers' bookings, and that inversion is the entire legal story. Reuters filed the story under litigation and Skift led on the AI-training purpose; @ThomasSmale put the price in context by noting JetBlue paid $58.5 million for 22 LaGuardia landing slots while the complete digital record of how the company operated went for $10 million.
The reason the customer data was carved out is ownership, not sensitivity - The sharpest line in the whole corpus is a comment on the r/ArtificialInteligence thread covering the sale: "you can regulate whether the customer data used for say customer service, can be sold as part of this or not... You cannot regulate corporate comms data sale - because company owns it free & clear." That is the actual doctrine. Section 363(b)(1) and the consumer privacy ombudsman created by BAPCPA in 2005 attach to personally identifiable information collected from individuals, which Hishaw Law describes as a role to "safeguard personal data during proceedings, particularly when sensitive information could be disclosed or transferred." An employee's Teams message about a delayed A320 is not information the debtor collected from a consumer. It is company property, and the statute has nothing to say about it.
The gate on this sale turned out to be a labor objection, not a privacy statute - The confirmation hearing set for today, 19 August, was pushed to 9 September after the Association of Flight Attendants-CWA filed an objection, per Aviation Today and The Traveler. Forbes headlined the union calling the plan "outrageous," with AFA president Sara Nelson saying they are objecting to Google's attempt to buy data "that has no business being sold." Note what did the work here: not the ombudsman regime, not the FTC, not a privacy policy. A union with standing as a creditor and a members' interest in the record. That is a narrow and non-generalizable defense - most dead companies do not leave an organized workforce behind to object on their behalf.
Google chose and paid for the firm doing the deidentifying, and this appeared in exactly one source - The Next Web read the actual contract terms: Spirit must deliver data to "one or more third parties acceptable to or designated by Buyer," with the buyer "solely responsible for every cost of deidentification." Google has design approval, payment control and review rights over its own scrub. TNW's framing is the most quotable thing in the window: "None of that is improper... It is simply not what an independent audit sounds like." The same piece surfaces the technical catch nobody else covered - the scrub is required to preserve referential integrity across the data set, so pseudonymous records stay linked across emails, tickets, commits and payroll. The property that makes the archive worth $10 million to a model trainer is the same property that makes the anonymization fragile.
"Deidentified" is a process claim, and the research literature does not rate it highly - GDPR Advisor, dated 15 August, states plainly that "supposedly de-identified or synthetic datasets can be reverse-engineered when enough auxiliary information is available." The standing benchmark in the reidentification literature is that 99.98% of Americans can be reidentified from a handful of attributes, and adversarial LLM reidentification is now itself a published method for scoring how well clinical text was anonymized (DIRI, arXiv). There is also a precedent hiding in plain sight: the Enron corpus, roughly 500,000 emails from about 150 senior staff, is the field's canonical PII detection benchmark and exists only because a company collapsed and its inbox became a public record. The Spirit archive is that, times two hundred, in private hands.
The one completed run of this machine, 23andMe, ended in voluntary commitments and settlements rather than a blocked sale - The genetic data did get sold: roughly $305 million to TTAM Research Institute, a nonprofit run by co-founder Anne Wojcicki, court-approved in late June 2025 and closed that July, with the buyer committing to comply with the existing privacy policy and to keep offering deletion rights - what Paubox calls "the buyer publicly committing to preserve existing customer data choices." The money that actually moved was compensatory and after the fact: 42 attorneys general settled for $18 million over the 2023 breach affecting 6.9 million customers, and a $46.75 million consumer class settlement got final approval on 30 January 2026. The lesson the The Fall Files video states better than any law-firm memo: "A privacy policy is not a property right. It is a contract with a specific company, and nearly all of them contain a clause saying your information may transfer if the business is sold." The precedent chain runs Toysmart 2000 to RadioShack 2015 to 23andMe 2025, and in all three the outcome was conditions on the buyer, never an unsalable asset.
The framing that moved on X is employment, not consumer privacy - @vpnguider drew the practical conclusion: "workplace emails, chats, and files usually belong to the company not the employee. Treat every work message like something that may outlive your job." @_shikhar_jais named the gap: "Nobody who wrote those emails agreed to become AI training material. That's the privacy question no policy answers." @LoadingAI_ called bankruptcy auctions "quietly becoming where tech companies go shopping for training data," @AlphaWireNewsAi called the result "cyber immortality," and @HochstatMichael did the only arithmetic anyone did: $10 million over roughly 600 million communications records works out to about 1.7 cents per item. On the supply side, Polymarket is pricing the next candidates - Frontier at 7.0%, JetBlue at 4.1%, Alaska at 2.4% for a bankruptcy announcement by 31 December, the whole market down 1.0% this month.
Honest note: there is no community layer on this topic, and the best evidence is a court docket and one blog - The Reddit return is a total miss. Twelve threads came back and every one of them is generic r/degoogle content about Android developer verification, LineageOS and browser picks, with zero on-topic threads; the engine's own top-voices line reads r/degoogle, which is the tell. X looks healthy at 24 posts and 866 likes, but the likes are almost entirely in unrelated AI-finance posts - @porterstansb at 707 likes is about Intel and Nvidia raising capital - while every on-topic Spirit post is in the single digits and the biggest, @Newsforce, has 10. YouTube returned three videos totalling five views. The one real discussion venue is Hacker News, where The Register story took 586 points and 408 comments and Axios took 92 points and 38 comments. So treat the confident parts of this brief as sourced from filings, the FTC record and a single close contract read, not from any crowd.
KEY PATTERNS from the research: 1. The $10 million package is employee work product, not customer records - 100M emails and 500M Teams messages in, 97.5M passengers and 52.4M loyalty members out, per Bloomberg Law. 2. The deciding variable is who owns the record: BAPCPA's consumer privacy ombudsman covers PII collected from individuals, and corporate comms fall outside it entirely - "the company owns it free & clear," per r/ArtificialInteligence. 3. What actually stalled the sale was a union objection, not a privacy rule - the hearing moved from 19 August to 9 September, per Aviation Today. 4. The buyer designated and paid for its own deidentifier and the scrub preserves referential integrity across the archive - "not what an independent audit sounds like," per The Next Web. 5. Deidentification is a claim about process, and the literature says auxiliary information reverses it - per GDPR Advisor, against a 99.98% reidentification baseline. 6. Toysmart, RadioShack and 23andMe all ended in conditions on the buyer, never a blocked sale; 23andMe's data moved for ~$305 million and the redress arrived later as $18 million from 42 AGs plus a $46.75 million class settlement. 7. A privacy policy is a contract with a specific corporate entity, not a property right that survives it - per The Fall Files on YouTube. 8. There is effectively no community discussion of this: 12 Reddit threads, all off-topic; the only real venue is Hacker News, where the story drew 586 points and 408 comments.