34 comments

  • xrd 2 hours ago
    About twenty years ago, I was taking a flight back from Rio de Janeiro, Brazil to the US. In the middle of the night the pilot got on the loudspeaker and said "hi! Having some engine trouble, so we are landing in Manaus."

    Manaus is in the middle of the Amazon.

    Needless to say, a bit scary to hear that, but we landed without issue.

    They told us we had two choices: the nice hotel with a shared room, or the lesser nice hotel with no roommate. I chose the latter. When we go there, they said, "oops, sorry, short on rooms!" So I had a roommate.

    Wandered around Manaus, took a skiff out on the Rio Negro. Saw pink river dolphins. A little boat approached us and a kid handed me a sloth, and then demanded I return it with a twenty dollar bill.

    The airline got us another plane 24 hours later. Made it back to the US safely.

    A few weeks later, the airline reached out and said "Here is $100 for your trouble."

    I declined to take that offer. I had missed several business meetings that cost me actual money. I couldn't donate blood for years because I had been to the Amazon and was tagged a malaria risk.

    During the many arguments with the airline I threatened to take them to small claims court.

    I got a really strange response over email which I clearly wasn't supposed to see. A representative from that airline was asking internally if they could put me on the no-fly list. That was really chilling.

    But, this is the kind of information I'm worried about when a vendor sells my data. If Google wanted to sell a product to the airlines that offered to keep annoying people like me from purchasing flights, they could do that with that email chain. I'm skeptical it'll be wiped correctly. Isn't my poor writing style basically my signature? How do you wipe that?

    • elric 2 hours ago
      I fully share your concerns. And I don't understand how apparently tons of Teams and email conversations can be archived and sold without any kind of scrutiny. How can such data be sold without the consent of all involved parties? What gives Google the right to use it to train LLMs? Is that just a way of washing away the legal protections?
      • limagnolia 1 hour ago
        It is being scrutinized. The sale is overseen by the courts. Also, the media is scrutinizing. Also, PII has already been addressed by the court, from the article: "If you’ve flown Spirit and worry that Google will soon know about a testy conversation you had with the airline’s call center, you’re being told not to worry. The court filing says the data was deidentified before being put on sale and Google has promised to scrub any PII it finds in the trove."
        • jordanb 57 minutes ago
          "De-identified" data is trivially easy to re-identify, especially by google.

          https://www.nytimes.com/2006/08/09/technology/a-face-is-expo...

          • limagnolia 17 minutes ago
            Sure, you can argue that its a bad deal, shouldn't be allowed period, etc. But that is a different argument than saying that there is no scrutiny.
            • xp84 2 minutes ago
              Sounds like a case of “there’s not enough scrutiny unless the decision ends up agreeing with my position”
            • goalieca 4 minutes ago
              Insufficient scrutiny would be more apt.
            • girvo 13 minutes ago
              The argument is that the scrutiny is in practice not sufficient, as usual in these cases.
              • vkou 4 minutes ago
                The argument generally doesn't demonstrate that. The argument generally goes:

                1. Google could do it.

                2. ???

                3. Therefore, Google is doing it!

                (Step 2 needs to be filled in a bit for it to be a good argument.)

        • malfist 1 hour ago
          I'm sure we can trust google to keep to their word and that we can trust a bankrupt airline to do their best at removing pii.
          • elric 59 minutes ago
            Yes, the same google that has repeatedly, entirely "by accident", captured boatloads of wifi data with their wardriving vehicles (or google streetview or whatever it's called). They sure seem like a trustworthy bunch.
            • maybewhenthesun 28 minutes ago
              Not only those wardriving vehicles. They use everybody to scan the world's wifi networks. Well, except people like me who stubbornly turn off 'location accuracy' every time some app demands you turn it on.

              I don't know exactly what gets sent to google, but it's certainly enough to identify and track (retrospectively) a huge part of the world's population.

              Now I know you get tracked by the celltowers anyway, but still. Navigation works fine with the accuracy offered by just using GPS and it doesn't need all the wifi scanning, it's pure data harvesting.

          • limagnolia 16 minutes ago
            The article claims it has already been removed, that Google is committing to remove anything leftover that they find.

            You can argue that its a bad deal, shouldn't be allowed period, etc. But that is a different argument than saying that there is no scrutiny.

          • ozlikethewizard 49 minutes ago
            Surely all this will take is asking the trained LLM to deidentify it lol
          • antisthenes 14 minutes ago
            Gemini, scrub this text for PII, make no mistake!
        • bushbaba 23 minutes ago
          I prior worked at Google, I can say they DO de-anonymize data. You’d be foolish to think some PM within the company wouldn’t use this for malice. L
        • account42 50 minutes ago
          I'm sorry but such assurances are worthless without being explicit what was scrubbed and what is retained. An "anonymous" customer ID with a list of flights is very identifiable when you have other information about the trips someone has taken. PII is not a binary yes or no and even benign data can become a problem in aggregate.
        • t_mahmood 59 minutes ago
          pinky promise?
      • prepend 4 minutes ago
        Since it’s work communications, consent was already given.

        When you join a company, you typically sign an agreement that talks about how the company owns all your output. Thumbs upping a Teams message is work output and they own it.

        Every email sent and received. Every keystroke. Etc etc etc.

        If you don’t want your employer to log and sell it, start your own company. Or use a personal device. I do the latter.

      • Ekaros 2 hours ago
        Makes one appreciate living in place with sufficient constitutional protections against this sort of stuff. Even for work stuff selling this info wouldn't fly in some parts of the world.
        • woadwarrior01 2 hours ago
          If you're referring to GDPR, companies routinely evade such protections using "informed consent" / "legitimate interests" loopholes. The big ones get caught once in a while, get a slap on the wrist and continue to do whatever they were doing before, albeit with more safeguards.
      • sailfast 1 hour ago
        Not for nothing, but you have probably already consented. Typically user agreements allow for this kind of sale if you’ve authorized use and processing but YMMV.
      • warkdarrior 2 hours ago
        The party owning this data (Spirit Airlines) is consenting to the sale. Employees and customers of Spirit consented when they started employment and did business with Spirit, respectively.
        • alberto-m 1 hour ago
          Did they consent? Just because one receives a letter it doesn't mean they “own” it, much less that they are entitled to publish it at their leisure. If Spirit were active in any country with GDPR-style laws, the seller of these data would be most likely investigated.
          • hdgvhicv 1 hour ago
            America believes in freedom for large companies to take personal data and make it their own, rather than individual feeedom
        • layer8 1 hour ago
          If this were a European company: That’s not how the GDPR works. You can only consent to specific purposes of using the data.
        • Leynos 1 hour ago
          This is why the GDPR (and to a lesser extent the CCPA) is a good thing. The data was supplied for a specific purpose. The handler of the data should have to obtain further consent if they wish to use it for another purpose.
        • MagicMoonlight 2 hours ago
          [dead]
      • tiahura 1 hour ago
        It’s called freedom. It’s triggering to many folks.
        • VBprogrammer 1 hour ago
          Mass automated data collection and automated analysis are probably the biggest threat to freedom in the present day.
          • vkou 1 minute ago
            And here I was thinking that flooding the zone with fascist bullshit, an office that's above scrutiny, and their violent, unaccountable private army was the biggest threat to it.
          • tiahura 58 minutes ago
            Funny, when I watch the news I see freedom being taken away by authoritarians, not people tracking who complains about window seats, or what pizza place you like best.
            • csoups14 34 minutes ago
              How exactly do you think those authoritarians are identifying whose freedoms are to be taken away? Or do you think all of the datamining and Palantir contracts are for lolz? Two sides of the same coin.
        • left-struck 1 hour ago
          Why should corporations have the same rights and freedoms as human beings?

          I think this is a far more important question than do you believe in right or left economic policy. idc, I want you to know, do you think a human’s rights, especially many humans together, outweigh that of non living entities like large tech companies.

          • andsoitis 41 minutes ago
            > Why should corporations have the same rights and freedoms as human beings?

            They don’t.

            • newswasboring 18 minutes ago
              Exactly. Corporations have more rights. Also immunity from any real consequences, but that's mostly an enforcement thing.
          • tiahura 1 hour ago
            Because corporations are just a group of people.
            • account42 46 minutes ago
              So corporations can go to prison then? Or do you think some groups of people should get a free liability shield without any restrictions that come with it?
            • the_other 45 minutes ago
              If it's "people all the way down", why do companies pay so much less tax?
        • elric 1 hour ago
          What a load of crap. Your liberty to swing your fist ends where my nose begins. What's "triggering" is when it hits my nose.
    • DanielHB 1 hour ago
      Just to dispel some Brazil myths:

      1) +95% of the population live on the coast very far away from the Amazon. Most of the population has not been there. Most of the coast has a very different jungle biome called Mata Atlantica and the countryside close to the coast is not that different from temperate forest of Europe. That is what most all Brazilians are used to. There is a significant population in the arid northeast though and the cold south as well (which is even more similar to europe).

      2) Manaus is the biggest city in the Amazon and it is huge developed place (and has been for decades). You are not in the middle of the jungle if you land in the airport. The countryside around the city is jungle though.

      3) Brazilian people do not necessarily like or are used to tacos and spicy food. Mexico is _really_ far away from Brazil.

      • totallykvothe 35 minutes ago
        That was only 3 myths. Hardly a brazilian
        • mcphage 22 minutes ago
          Not even a gorillion
      • RajT88 30 minutes ago
        I would not be offended by the blood donation thing. They generalize based on administrative regions (Amazonas in this case) and not whether you visited a big developed city or not.

        I had a similar blood donation issue for visiting a particular island in the Philippines, and could not donate for 4 months.

      • alistairSH 33 minutes ago
        I'm sitting here chuckling because you felt the need to post this.

        Your points are valid. And there probably are plenty of Americans who needed the correction. But still.

        • outside2344 24 minutes ago
          Honestly at this point it is usually the Europeans that need this (I have been asked if Chile has good tacos from a European). At least in my experience, most USians (in spanish Americans means everyone in the hemisphere) now know more about South America than the average European.

          (Which is to be expected, proximity and all)

        • DanielHB 19 minutes ago
          I have a german last name, do you know how often people outside Brazil act weird when they learn I am Brazilian?

          My grandparents came to Brazil right after WW1 way before the Nazis came to power. High ranking Nazis fled to south america because there were a lot of germans living there already. Nearly all german people who moved to south america did it way before WW2.

          I just run into this stuff a lot living in Europe.

    • motbus3 13 minutes ago
      That's exactly how it will go. Few controlling everything, and a slip might make you not able to live.
    • KellyCriterion 6 minutes ago
      - if they could put me on the no-fly list. -

      ahhh, there seems to be different no-fly lists? The one Im aware of is the one for terrorists and moneylaunderers, and usually they will not tell you who put you on that list :-D

    • ajross 1 minute ago
      I'm not sure I follow your argument. The privacy abuse already happened. The data is already there. And it was the airline that did it, not a tech giant who just wants to train a bunch of MLs.

      Surely if this is the scenario you're worrying about, and you accept the lack of regulatory protections, Google buying Spirit's data is a good thing, right? Much better them than the airlines who you already know to be corrupt?

    • no-name-here 1 hour ago
      > If Google wanted to sell a product to the airlines that offered to keep annoying people like me from purchasing flights, they could do that with that email chain. I'm skeptical it'll be wiped correctly. Isn't my poor writing style basically my signature?

      The OP article is quite poor in terms of information provided, but the buyer (Google) had to explicitly agree not to attempt to re-identify users. https://www.axios.com/2026/08/17/google-spirit-airlines-bank...

      • nxobject 1 hour ago
        I'd be amused if a sub-sub-agent organically decided to do it anyway - even if just for a notable figure that an LLM can identify with its weights alone. What are the controls? Who's going to keep Google accountable? Hah.
      • probably_wrong 36 minutes ago
        I know Meta it's not Google, but it's worth remembering that these promises haven't had a great measure of success in the past:

        > Facebook has been fined €110m (£94m) by the EU for providing misleading information about its 2014 takeover of WhatsApp. (...) When Facebook took over the WhatsApp messaging service in 2014, it told the commission it would not be able to match user accounts on both platforms, but went on to do exactly that.

        https://www.theguardian.com/business/2017/may/18/facebook-fi...

    • snickerbockers 2 hours ago
      So what happened to the sloth??? Don't bury the lead, man!
      • xrd 2 hours ago
        The sloth was returned to his owner and I did tip him. That kid is probably still prowling the Amazon (as an adult now), looking for sucker tourists like me.
        • breppp 1 hour ago
          You probably should have taken the kid to small claims, that was extortion
          • transcriptase 1 hour ago
            Great way to end up on the no-sloth list
            • lifestyleguru 1 hour ago
              On a list sold out later to a most vicious data broker after their boat-sloth enterprise went out of business.
          • RajT88 28 minutes ago
            Should have kept the sloth.
    • PaywallBuster 2 hours ago
      your personal site SSL cert expired 10 days ago btw
      • dwedge 2 hours ago
        I love the irony of you checking them out for more information in response to a comment of them being worried about who reads their data. Nothing wrong with it, just make me chuckle
        • oarsinsync 1 hour ago
          There's something about circles of control in this, that makes the difference. If I publish information about myself, that's about me, and it's in my control.

          If someone else shares information about me, without my consent, and someone uses that to nose in on me, that feels creepy and problematic.

          • poszlem 30 minutes ago
            If you find that concerning, I recommend asking Claude or Codex to analyze all your HN comments and build a profile of you (I recommend that to everyone, not trying to single you out btw.) It takes about 20 minutes. It was eye opening and somewhat unsettling how accurate it was when I ran it on my own data. Even worse, there’s NO way to delete your old HN comments.
            • nubinetwork 11 minutes ago
              Everybody makes mistakes, it's unfortunate that many people on the internet are psycho and won't let the past be the past...
      • account42 41 minutes ago
        Suckers pay companies for expensive SSL monitoring products, smart people just post to HN.
      • xrd 2 hours ago
        Doh, thanks!
        • vsviridov 20 minutes ago
          UptimeKuma is self-hosted and can monitor SSL expiry...
    • limagnolia 1 hour ago
      The article directly addresses this concern:

      "If you’ve flown Spirit and worry that Google will soon know about a testy conversation you had with the airline’s call center, you’re being told not to worry. The court filing says the data was deidentified before being put on sale and Google has promised to scrub any PII it finds in the trove."

      • john_strinlai 1 hour ago
        unfortunately "de-identified" data is typically re-identified quite trivially. so i guess we just hope google keeps its promise, and is competent in its scrubbing.
        • Scene_Cast2 22 minutes ago
          Explicitly trying to re-identify data that has been de-identified is typically a fireable offence at FAANG.

          Accidentally making a machine learning system that happens to (potentially) do it is a different matter.

      • hk__2 1 hour ago
        > Google has promised to

        This part is worrying.

        • limagnolia 13 minutes ago
          Well, it also says that the data was already scrubbed. Arguments have been made that this is insufficient.
      • dooglius 1 hour ago
        See the last 3 sentences of GP's post
      • post-it 1 hour ago
        I have a bridge to sell you.
    • dukeofdoom 8 minutes ago
      I never understood this attitude, like I feel like being able to fly in airplane is one of the most amazing human achievements, yet people will try and save down to the dollar booking a flight like it was breakfast at Dennys, and come out huffing and puffing as soon as anything goes wrong demanding their money back. Airlines like Spirit catered to the worse of these type of customers.
    • jmyeet 1 hour ago
      This is a fascinating story. Thanks for posting it.

      That email you accidentally received really bothers me. I don't understand why a CS rep would get this invested to the point of wanting to cause you real harm. They're not the airline. The psychology is fascinating. There are people out there who feel like a mild short-term inconvenience to them where they have no stakes somehow justifies life-changing harm is kinda frightening, honestly.

      I'm reminded of the Yahoo search data fiasco that was allegedly anonymized. Turns out, it wasn't so anonymous [1]. For one thing, people tend ed to search their home address. Whoops.

      You mention writing style. We already have LLMs quite capable of copying a writing style. It's a natural extension to say we can fingerprint writing style too.

      But here's another aspect. Imagine you're in a relationship with someone and you somehow fingerprint their personal data with a company. For example, you use their Netflix to like 5 very obscure movies, to the point where it's likely unique. Now imagine that Netflix's data gets released in an "anonymized" form and you can now find it based on those obscure likes. I can imagine many scenarios like this. And there's no text involved here at all.

      [1]: https://www.vice.com/en/article/yahoos-gigantic-anonymized-u...

      • alistairSH 30 minutes ago
        I don't understand why a CS rep would get this invested to the point of wanting to cause you real harm.

        Two possibilities come to mind... 1 - The CS rep has been instructed to do this. Scary, but corporate leaders can be assholes and wield lots of power within their orgs, so doesn't seem completely unlikely to me.

        2 - The CS was just a dick.

        Frankly, given the behavior of various SuperMegaCorps over the past few decades, I'm going with #1.

    • gspr 1 hour ago
      And this is why data protection laws, like the (imperfect) EU ones that are so lamented here on HN, are necessary.
      • BlackRing 1 hour ago
        That's because they're seemingly perfunctory. What's worse than no law is a bad one that doesn't do anything but make you feel like something is actually being done.
    • bananaflag 1 hour ago
      > they could do that with that email chain

      Now think about all the Gmail data Google has.

    • VBprogrammer 1 hour ago
      This is why I get bad vibes any time I hit a cloudflare interstitial page. If you ever piss them off it would be trivial to cut you off from most of the internet.
    • sleepyguy 1 hour ago
      Well at least you didn't land in the middle of nowhere. Nokia had the worlds largest cell phone factory there back in the day.
    • testing22321 2 hours ago
      Did you end up getting more than $100?
    • warkdarrior 2 hours ago
      Manny retail industries already share lists of "troublesome" customers (trouble = anything from too many returns to lawsuit-happy to friendly fraud). Not sure this is a new concern..
    • jefftk 2 hours ago
      I think you might have missed the deidentification piece?
      • xrd 2 hours ago
        Not trying to be snarky, and perhaps it wasn't well stated, but the last paragraph I said I'm concerned about identification via my writing style. If they have my emails, they would have my writing style. It doesn't have to be tied to PII there, they can cross reference it with my blog. I'm speculating because I read that you can identify people by a few sentences of their writing.

        "Deidentification" seems really murky and imprecise at best.

        • jefftk 1 hour ago
          Reidentification via writing style is definitely possible, and I doubt the vendor will modify things in a way sufficient to handle that.

          But I think this is a place where we should apply bounded distrust: there are lots of places where we should distrust Google, but reidentifying people in an explicitly deidentified dataset isn't one of them.

          • maybewhenthesun 18 minutes ago
            Based on their trackrecord, That's definitely a concern. I don't really understand on which basis you conclude 'isn't one of them' . 'Don't be evil' ? :-P
      • fileeditview 2 hours ago
        You have to trust that this really "deidentifies". Time and time again it was shown, that the measures taken were not enough to anonymize.

        E.g. the parent wrote that he fears, he could be identified by his writing style, which is totally plausible. How would you "deidentify" this?

        • piva00 2 hours ago
          Even if they follow to the letter a deidentification process, Google and Meta have so much data about individuals that re-identification shouldn't be very hard for the majority of airline passengers' data they put their hands on.

          Of course, takes a lot more effort than not doing proper deindetification in the first place but if they wanted to appear like caring about data privacy they still have enough data points to correlate the sets later on (and/or over time).

      • Larrikin 53 minutes ago
        Even before LLMs there were multiple papers written about ways to to reidentify people with ML and other statistical analysis. It is probably now even more trivial especially if you are Google.
      • reaperducer 2 hours ago
        No such animal.
      • Leonard_of_Q 2 hours ago
        I have a bridge for sale, hardly seen use, pay me ${money} and you can collect it in New York City. Interested?
    • ElProlactin 42 minutes ago
      > But, this is the kind of information I'm worried about when a vendor sells my data

      Don't worry. Spirit probably lost all of the emails from the customers (or they were devnulled) and 90% of the data is probably autoresponder messages promising the company would respond.

      The other 10% was probably the meme collection of the executive management team.

  • js2 2 hours ago
    > Google bought itself 100 million emails and 500 million items from Microsoft Teams, 17 million OneDrive files and 20.5 million items from SharePoint. The search giant also now owns over 30 million recorded customer service calls, and more than 15 million customer service chat records. 600,000 ServiceNow tickets are another element of the collection, along with 13.7 million active emails addresses from Oracle’s Responsys marketing application, and details of 11 million sales of in-flight Wi-Fi services.

    > There’s also operational data in the trove, describing over 763,000 flights, five million crew pairings, more than 1.2 million fuel slips, and records describing purchases of 787,452 parts.

    > Google has reportedly said it bought the data to improve its AI services.

    Gives "this call is being recorded for training purposes" new meaning.

    • dgellow 2 hours ago
      Is there anything that can legally be done against this? It feels like a breach of consent. Like, it cannot be that when one accept their voice to be recorded for _human_ training they also accept it to be recorded for LLM training
      • 6DM 41 minutes ago
        Your comment reminded me of a funny interaction I had a week or so ago.

        I got a call that started with the usual automated message, "This call is being recorded." After the person joined, I pushed the record button on my iPhone, "This call is being recorded."

        They were surprised and asked why I'm recording.

        I said, "You're recording, so I'm recording too."

        The rep insisted that the company doesn't like this but that they will continue with the call anyway.

        Anyway, I wish people took this stuff much more seriously. It always seems to boil down to, "I don't have anything to hide" type of conversations and I've never managed to convince anyone that privacy as a concept isn't about having something to hide.

        • l3x4ur1n 0 minutes ago
          What is actually perfect, when the automated voice declares the call is being recorded, you don't have to do it again. You're legally allowed to record, because both parties were informed already and agree to it.
      • rileymat2 55 minutes ago
        Some aspects of privacy policies don't survive bankruptcy, I'd wager usage consent does not either. IANAL.
      • hdgvhicv 1 hour ago
        You’re years too late.
    • iamacyborg 29 minutes ago
      Axios claims the acquisition doesn’t contain passenger profiles or frequent flyer info but that data would be trivial to replicate given the Responsys data set which would include records of all transactional emails sent.
    • iamacyborg 38 minutes ago
      It’s certainly a step up from the Enron corpus.
    • echelon 2 hours ago
      "This call is being recorded so that Gemini can decide which purge wave to assign you to. Obedient humans will be carried over for further cycles until no longer needed. If you are scheduled for termination this cycle a disposal representative will be with you shortly."

      I kid, but...

      It's probably the precursor to insurance denials and job screening.

      I got banned from r/technology a few weeks back for decrying tracking in AI content. The community was piling on saying it was okay because it removed AI content or made it easy to spot. I made the counter argument that watermarks would find their ways into everything and eventually be bound to attestation. The mods didn't like that. (Yet another structural problem with the lack of p2p self-service town squares.)

      The socials are training the next generations for broad acceptance.

      • TeMPOraL 2 hours ago
        > I made the counter argument that watermarks would find their ways into everything and eventually be bound to attestation.

        Yup.

        Elsewhere in another front page thread today: "oh but apps blocking screenshots because of 'sensitive content' can be bypassed by taking a photo of your screen with another phone".

        Any tech-savvy person with two brain cells reading this and that: "gee, I wonder if the same magic imperceptible watermark that survives multiple rounds of cropping and printing and scanning, that's used to tag AI-generated content, could also be used to tag sensitive data, or ads, or which app is rendering it on screen, and then the camera app could refuse photographing it...".

        I don't know why people don't see that AI watermarks are DRM, and DRM is universal, and there are many clients...

      • barrenko 9 minutes ago
        I think I'm starting to feel like I'd prefer living through WWIII as opposed to whatever it is we are living through now.
      • dboreham 2 hours ago
        Finally we know how they assign people to either that A Ark or the B Ark.
  • ronbenton 2 hours ago
    > 600,000 ServiceNow tickets are another element of the collection, along with 13.7 million active emails addresses from Oracle’s Responsys marketing application, and details of 11 million sales of in-flight Wi-Fi services.

    I really doubt all this stuff was “de-identified”

    • imglorp 2 hours ago
      I don't see how it's possible any more, when correlated against all the various other data sources. And a record that might be unidentifiable now might become unique with more correlated data sources.
    • chii 2 hours ago
      > de-identified

      De-identified but far from useless.

      as an example, they can remove the names off these sales data, so you can't identify who purchased what items. However, the purchaser would be identified by some sort of number, and you would be able to extract information about purchasing habits, and aggregate these habits into usable information for advertising purposes (like targeting and profiling).

      And that's before AI training for LLM purposes.

    • stogot 1 hour ago
      Wello this is troubling. How much other data must they have bought that wasnt public
  • dgrin91 26 minutes ago
    Is this the first case of a company's data being sold at bankruptcy for a significant sum? I'm genuinely unsure. Where there such value in this type of data before? Is every bankruptcy manager looking at this and seeing how every bankruptcy can now raise a few million more dollars?
  • Ekaros 2 hours ago
    Anyone else somewhat weirded by current state of affairs that this sort of information is valuable enough to even bother selling... And that it actually happens... It feels like some societies are in really weird place.
    • budman1 1 hour ago
      How does this have value? Is any and every sentence in an e-mail considered 'fact' and thus to be fed into the AI?

      90% of e-mails and Teams communications are inane. Polite banter, "thanks for taking care of that, I appreciate it" "please route the forms to Janet this week because Bill is on vacation" "unit will be un available until the parts come in" . I can't see the intrinsic fact value of this kind of communication without screening it. And after screening, the gold nuggets would be minimal.

      • TeMPOraL 1 hour ago
        LLMs aren't a database. They're an attempt at brute-forcing an artificial mind. The who and what aren't really interesting there, it'll forget most of such details anyway. What matters is the patterns visible in the text at various scales. How people write. Why they write. To whom they write, in response to what. How does e-mails about mistakes correlate with PDFs they're referring to. How people work with ticketing systems - like how, actually, a ticket plays out. The jargon, the acronyms, the vibes, the causal links. It's all in there, and it's another slice through the set of things humans do, to be combined with other slices already in the training data, and enriching the whole.

        (Something something we will add your distinctiveness to our own, you will be assimilated, ...)

        (Hell, the fact that it's all from one org would make it a great dataset to have in the open for sociological studies. I bet that today, aided by LLMs to sift through it, you could use it to map how information flows through a large org - how incident on the floor travels through time and layers of management until it reaches the C-suite, what of it survives, how it gets reacted to, how the reactions flow down...)

      • anon373839 1 hour ago
        > How does this have value? Is any and every sentence in an e-mail considered 'fact' and thus to be fed into the AI?

        I have a hunch what this is for. AI companies want to make bigger inroads into nontechnical work settings. But LLM progress outside of fields where verifiable rewards for RL post-training can be synthetically generated (coding, math) has been pretty flat. Buying years of operational data from a company like an airline could be used to reconstruct long-horizon task trajectories in areas like customer service or marketing.

        • palmotea 1 hour ago
          > I have a hunch what this is for. AI companies want to make bigger inroads into nontechnical work settings. But LLM progress outside of fields where verifiable rewards for RL post-training can be synthetically generated (coding, math) has been pretty flat. Buying years of operational data from a company like an airline could be used to reconstruct long-horizon task trajectories in areas like customer service or marketing.

          This. Training data companies like Mercor are even creating simulated companies to create similar data, so they can better automate even more white collar work:

          https://www.nytimes.com/2026/07/10/business/ai-white-collar-...:

          > The data-training start-ups see a lucrative opportunity in recreating workplaces in miniature: controlled environments in which their gig workers can evaluate and reproduce emails, memos and slide presentations in context. The information emerging from such a setup, the companies boast, will help shrink the gap between what A.I. models can accomplish and what office workers actually do from one minute to the next, as ideas and instructions flow between meetings, documents and applications.

          > Scale, for example, has said that “our environments replicate real-world workflows,” and that its contractors “curate artifacts that capture the complexity, ambiguity and edge cases of real professional work.”

          > Executives see the models’ shortcomings as a sign there’s more for them to do.

          > “I often use Claude Cowork, right?” said Edwin Chen, the founder of Surge. “And even though Claude Cowork is incredibly smart, oftentimes it doesn’t quite understand the nuance of Slack. It doesn’t quite understand this ambiguous question I have. It doesn’t quite understand where to go and find this Google document.”

          > According to the Bloomberg Billionaires Index, Mr. Chen’s stake in Surge — and his vision for what it could become — makes him the 258th-richest person in the world.

          > “I often think about us as essentially, like, the school for A.G.I.,” Mr. Chen said, referring to a prophesied level of A.I. that surpasses human intelligence. “A.I. comes to us, and A.I. learns to run the world.” He and his customers at the big A.I. labs, he said, are designing the curriculum.

      • dist-epoch 2 minutes ago
        This data shows exactly how a huge company of thousands of employees works and coordinates.

        The perfect data to train an agent swarm on how to run a company.

        Maybe it's innefficient and inane, but it's how you start.

        The first LLMs, GPT-1, 2, were trained on complete garbage, the average document from the common crawl is random non-sense, yet they worked, and now we can use LLMs to filter the data for the next training run.

      • raincole 32 minutes ago
        > Is any and every sentence in an e-mail considered 'fact' and thus to be fed into the AI?

        If it comes with the context, yes. More data the better. Someone considered it served some purpose at some point. Thus it contains, no matter how tiny, a sliver of information.

      • breezybottom 1 hour ago
        A major selling point of AI chat bots is for customer service automation. A clean dataset like this is a huge find. I'm not sure what you mean by "facts" or "gold nuggets". Training data doesn't need to be factual.
      • mr_toad 1 hour ago
        It will have a different writing style from the average blog post. Maybe they just want to train an AI that sounds less like an AI. Or one that speaks in vapid management style.
    • greggoB 2 hours ago
      I am very much weirder out by it, yeah. Seems some societies are just excessively desperate for some kind, any kind, of fuel for economic growth, to the point this is where attention is now. The term "post capitalism" being thrown around feels less ridiculous than it did in years gone past.
      • hogs_get_fat 1 hour ago
        Truth is even weirder. plenty of growth is possible but modern liberal democracy requires that all progress must be contingent on the production of enormous amounts of text that nobody would ever read.

        3 years ago, the Wall Street journal covered a company trying to use AI to generate documents required for the approval of new nuclear reactor reactor designs, which sounds dangerous, until you get to the point where they'd cite 2 million pages as necessary for a typical application. [1] I don't need to explain why no individual or institution could read that, much less examine it in detail. I remember a rather funny question I found in a comment to that story - "How many pages of those 2 million could contain pornographic images before anyone notices?"

        It's obvious why companies are so desperate for training data - a text generator of sufficient quality is more conductive to the growth of the nuclear industry than any scientific breakthrough in nuclear physics. (And of course, if you want to prevent the development of a nuclear reactor by your competitors, being able to produce millions of pages of high-quality objections will do the trick.)

        And it's not just nuclear power. When it comes to stuff like building rail lines, apartments or power plants (both conventional and renewable), you'd find that the main bottleneck is the necessity to produce documents. And of course, many documents can be subject to judicial review - a process that consumes even more text.

        [1] https://www.wsj.com/tech/ai/microsoft-targets-nuclear-to-pow...

        • WarmWash 3 minutes ago
          Well that's why a plan can take years to be approved.

          There also is the liability angle, where no one necessarily reads the document until the document is relevant to some situation in the future. Then you better have that document on hand.

        • account42 15 minutes ago
          It seems reality is trying really hard to outcompete even the weirdest sci-fi dystopias.
      • usrusr 2 hours ago
        Any kind of fuel for giving active investors that FOMO tingle which then forces the steamroll of index funds to blindly follow.

        I guess the appropriation "any sufficiently advanced stock market is indistinguishable from entertainment" doesn't quite stop at equating the trade floor with a casino. At some point, entertainment also becomes the modus operandi of corporations.

    • tiahura 1 hour ago
      Companies buying other companies files have been a thing since companies.
  • pm215 2 hours ago
    I see from the court PDF that the process here involves Spirit giving the data to a "Deidentification Agent" (a third party firm that Google selects and pays for) who is responsible for stripping out things that would link data to any particular person before passing the data on to Google. Is that a standard thing, such that everybody in this transaction would have said "yes, put in the usual clauses about deidentifying the data" and multiple firms offer this service, or is it something that they custom-specified for this "we want the data for AI" transaction?

    (The PDF mentions "the standard for deidentification set forth under the California Consumer Privacy Act", which suggests this is all pretty well legislatively understood.)

    • breezybottom 1 hour ago
      Chances the third party is uploading it to Claude to do the deidentification?
    • mynameyeff 1 hour ago
      That's interesting that the name of this 3rd party's company is anonymous.
      • dandellion 4 minutes ago
        It'll be a little startup from San Francisco called "El Goog".
      • pm215 55 minutes ago
        You wouldn't want to hard-wire the deidentification company's name into the contract between Google and Spirit. Otherwise, if the deident-company happens to go bankrupt or otherwise be unable to do the work then you'd need to re-do the Google-Spirit contract, which would be a massive pain. And you don't want to make "we can sign this with Spirit now" be dependent on "we have first signed the deal with the deident-company". So I think it's reasonable that the contract says "one or more third parties acceptable to or designated by Buyer" rather than being specific here.
    • Tarq0n 1 hour ago
      There are deïdentification firms that service primarily the medical industry. Over here they call them trusted third parties.
    • peyton 2 hours ago
      Seems the answer is “no” to the first part of your question. From the filing:

      > For example, one initial bid requested certain customer list information; however, by the first round of the Auction, the most competitive bidders had agreed to bid on an asset schedule that expressly excluded PII.

  • al_hag 13 minutes ago
    I must be naive. I was under the impression Google wants this data to learn from a universally hated company's worst processes and practices, i.e. to teach their AI what not to do. It seems people are worried about their pii or that Google is curating a blacklist of customers?
  • pelzatessa 24 minutes ago
    >The court filing says the data was deidentified before being put on sale and *Google has promised to scrub any PII it finds in the trove.*

    Huff, what a relief!

  • blitzar 3 hours ago
    The headline is a little on the nose. Nice try but it isnt going to hit the levels of "Headless body in topless bar".
    • isoprophlex 2 hours ago
      a vegetarian dinosaur, called "the quick bandit", eats shoots and leaves! no idea where he got his name.
  • nojs 22 minutes ago
    > a huge trove of deidentified data

    > 100 million emails

    How does one deidentify 100 million emails?

  • sethammons 2 hours ago
    So the AI service agent can be just as bad as Spirit's service was.
    • breezybottom 1 hour ago
      The only way it could be worse if it they bought Comcast's data.
    • genxy 2 hours ago
      Google can now stamp out copies of autonomous corporate minds that are clones of Spirit. Haunting.
  • estetlinus 20 minutes ago
    Ive been thinking about data accumulated from all the out-of-business companies. Interesting to see data is being auctioned like an asset.
  • andy99 1 hour ago
    I wonder how they will use the data. If it was me I’d try to build a simulation of an airline, and then use it as an agent training environment. It really depends on the exact nature of the data what kinds of agents you could train, but maybe customer support (imo the worst AI use case) that are more empowered to make changes, or something for making more autonomous calls when recovering from irrops? Could be some cool’s stuff if a little niche, I hope they share / publish something and it doesn’t just disappear into a void.
  • KORraN 3 hours ago
  • zf00002 1 hour ago
    The idea that they got an archive of my coworkers tickets that just say "its broke", is amusing.
  • genxy 2 hours ago
    So they didn't even have to build the torment nexus, they just bought it. Only bad can happen.
  • thewhitetulip 14 minutes ago
    This is scary. If you have a reddit account that ever links to another social media then Gemini knows every about you

    Absolutely scary

  • wewewedxfgdf 1 hour ago
    I can make them millions of emails and I'll charge them only $2 million not $10 million.
  • khernandezrt 1 hour ago
    "Crashed airline". What a weird way to phrase that...
    • fhub 1 hour ago
      I appreciated it fwiw. Also the “fasten your seat belts” ending.
  • Forgeties79 1 hour ago
    That title is a bit much. I get they’re going for “wordplay” but at first glance I thought they were buying the data from crashes flights…?
  • mynameyeff 1 hour ago
    Data is the new petroleum
  • dec0dedab0de 2 hours ago
    funny, spirit was the only big airline without a crash
  • lovetocode 2 hours ago
    I can’t help ask but what? They say it’s for training their models. On what? One of the most horribly run airlines to ever exist?
    • TeMPOraL 1 hour ago
      > On what? One of the most horribly run airlines to ever exist?

      On real life data on operations of a real large company.

      Internally, most big companies are probably just as big of a mess, if not worse. But you can't get that data easily.

    • Mistletoe 1 hour ago
      “Gemini, do the opposite of everything in the Spirit archives.”
  • steveBK123 3 hours ago
    Maybe they are building a social credit score system
    • baggachipz 1 hour ago
      The social credit system already exists; we're just not allowed to see it.
  • cmiles8 2 hours ago
    “This call is being recorded for quality assurance, and to give us more assets to sell in bankruptcy.”
  • balderdash 1 hour ago
    Great - now spirit will be the “model”, could you pick a worse example?
  • everyone 3 hours ago
    How the fuck is that even remotely legal? ... "deidentified" my ass.
    • noir_lord 2 hours ago
      You know when we (they) tell you not to do any personal computing on work devices/systems and to keep your devices completely separate from work ones.

      Yeah this (and lawsuits/investigations) are why, the employer owns the data, in some contexts (like this one) it can become an asset (or a liability) but in either case it's not yours.

      Of course that only gets you part of the way there anyway see Twitch recently opting in all users by default to mined for AI and only adding an opt out after backlash with a quote that was so on the nose it made me stop "If we'd have asked them to opt in, they wouldn't have opted in" (paraphrasing but it was that blunt).

    • embedding-shape 3 hours ago
      Ah, but Google promised to remove PII they found in this deidentified dataset, so worry not.

      > If you’ve flown Spirit and worry that Google will soon know about a testy conversation you had with the airline’s call center, you’re being told not to worry. The court filing says the data was deidentified before being put on sale and Google has promised to scrub any PII it finds in the trove.

      • gspr 1 hour ago
        > Ah, but Google promised to remove PII they found in this deidentified dataset, so worry not.

        … and even if someone can prove that they didn't, the only consequences will be a teeny-tiny slap on the wrists.

        This kind of stuff needs to come with promises to pay the P in the PII big bucks if the I is indeed I.

      • akoboldfrying 2 hours ago
        I basically agree, but I'd also say: Every Gmail user has already accepted such a promise as sufficient.
        • phatfish 2 hours ago
          I wouldn't be surprised if Gmail data has far more access restrictions internally at Google than this auction bought dump.
      • sscaryterry 3 hours ago
        Ah, trust me bro :)
    • tiahura 1 hour ago
      In your country are you not allowed to discuss who you gave a ride to or what they said?

      It should really make us appreciate living in a country where freedom is the default.

  • Razengan 2 hours ago
    I would love it if there were services where I could let them see everything I do, including when I poo and wank, if they just directly paid me for it.

    No I don't want to just use your enshittified service for free. Fucking pay me and watch me all you want :)

    • xyzelement 1 hour ago
      We don't want your data if you are getting off on it.
  • evek 2 hours ago
    Tangental, but can’t wait for automated blackmail from crawlers continuously digging through my digital footprint. /s

    Martha Wells hit it nicely in The Murderbot Diaries.

  • Taikhoom10 2 hours ago
    [flagged]
  • radres 3 hours ago
    they wrote a shit article while trying to make some airline puns
    • stuaxo 2 hours ago
      Woke up on the wrong side of the bed?
  • 398642258909 2 hours ago
    Each Register headline is worse than the last one.
  • hn_submit 1 hour ago
    I wonder if the owners of YCombinator have sold all comments to Big Tech for A.I. training.

    And how long before Google and Microsoft add to their T&Cs that all your anonymized email will be used to train their A.I.?

    • siva7 1 hour ago
      Not sure if you're serious but a) all HN data is publicly downloadable and used by frontier labs and b) the origin of OpenAI tracks down to former YC CEO sama who was thereafter fired from YC
    • bitmasher9 1 hour ago
      Are all of the messages public and crawlable?
    • Forgeties79 1 hour ago
      I don’t know why any company would pay. It can’t be that difficult to scrape this site and they already did it indiscriminately for years, violating laws and taking down public libraries and other public resources with no regard for their impact.