upvote
I fully share your concerns. And I don't understand how apparently tons of Teams and email conversations can be archived and sold without any kind of scrutiny. How can such data be sold without the consent of all involved parties? What gives Google the right to use it to train LLMs? Is that just a way of washing away the legal protections?
reply
It is being scrutinized. The sale is overseen by the courts. Also, the media is scrutinizing. Also, PII has already been addressed by the court, from the article: "If you’ve flown Spirit and worry that Google will soon know about a testy conversation you had with the airline’s call center, you’re being told not to worry. The court filing says the data was deidentified before being put on sale and Google has promised to scrub any PII it finds in the trove."
reply
"De-identified" data is trivially easy to re-identify, especially by google.

https://www.nytimes.com/2006/08/09/technology/a-face-is-expo...

reply
Sure, you can argue that its a bad deal, shouldn't be allowed period, etc. But that is a different argument than saying that there is no scrutiny.
reply
The argument is that the scrutiny is in practice not sufficient, as usual in these cases.
reply
I'm sure we can trust google to keep to their word and that we can trust a bankrupt airline to do their best at removing pii.
reply
The article claims it has already been removed, that Google is committing to remove anything leftover that they find.

You can argue that its a bad deal, shouldn't be allowed period, etc. But that is a different argument than saying that there is no scrutiny.

reply
Yes, the same google that has repeatedly, entirely "by accident", captured boatloads of wifi data with their wardriving vehicles (or google streetview or whatever it's called). They sure seem like a trustworthy bunch.
reply
Not only those wardriving vehicles. They use everybody to scan the world's wifi networks. Well, except people like me who stubbornly turn off 'location accuracy' every time some app demands you turn it on.

I don't know exactly what gets sent to google, but it's certainly enough to identify and track (retrospectively) a huge part of the world's population.

Now I know you get tracked by the celltowers anyway, but still. Navigation works fine with the accuracy offered by just using GPS and it doesn't need all the wifi scanning, it's pure data harvesting.

reply
Gemini, scrub this text for PII, make no mistake!
reply
Surely all this will take is asking the trained LLM to deidentify it lol
reply
I prior worked at Google, I can say they DO de-anonymize data. You’d be foolish to think some PM within the company wouldn’t use this for malice. L
reply
I'm sorry but such assurances are worthless without being explicit what was scrubbed and what is retained. An "anonymous" customer ID with a list of flights is very identifiable when you have other information about the trips someone has taken. PII is not a binary yes or no and even benign data can become a problem in aggregate.
reply
pinky promise?
reply
Makes one appreciate living in place with sufficient constitutional protections against this sort of stuff. Even for work stuff selling this info wouldn't fly in some parts of the world.
reply
If you're referring to GDPR, companies routinely evade such protections using "informed consent" / "legitimate interests" loopholes. The big ones get caught once in a while, get a slap on the wrist and continue to do whatever they were doing before, albeit with more safeguards.
reply
Not really: https://noyb.eu/en/fines-resulting-noyb-litigation

Sure 50 M or even 1 B might be peanuts for faang but still there is real progress.

Support Noyb at all costs

reply
Not for nothing, but you have probably already consented. Typically user agreements allow for this kind of sale if you’ve authorized use and processing but YMMV.
reply
The party owning this data (Spirit Airlines) is consenting to the sale. Employees and customers of Spirit consented when they started employment and did business with Spirit, respectively.
reply
Did they consent? Just because one receives a letter it doesn't mean they “own” it, much less that they are entitled to publish it at their leisure. If Spirit were active in any country with GDPR-style laws, the seller of these data would be most likely investigated.
reply
America believes in freedom for large companies to take personal data and make it their own, rather than individual feeedom
reply
This is why the GDPR (and to a lesser extent the CCPA) is a good thing. The data was supplied for a specific purpose. The handler of the data should have to obtain further consent if they wish to use it for another purpose.
reply
If this were a European company: That’s not how the GDPR works. You can only consent to specific purposes of using the data.
reply
It’s called freedom. It’s triggering to many folks.
reply
Mass automated data collection and automated analysis are probably the biggest threat to freedom in the present day.
reply
Funny, when I watch the news I see freedom being taken away by authoritarians, not people tracking who complains about window seats, or what pizza place you like best.
reply
How exactly do you think those authoritarians are identifying whose freedoms are to be taken away? Or do you think all of the datamining and Palantir contracts are for lolz? Two sides of the same coin.
reply
Why should corporations have the same rights and freedoms as human beings?

I think this is a far more important question than do you believe in right or left economic policy. idc, I want you to know, do you think a human’s rights, especially many humans together, outweigh that of non living entities like large tech companies.

reply
> Why should corporations have the same rights and freedoms as human beings?

They don’t.

reply
Exactly. Corporations have more rights. Also immunity from any real consequences, but that's mostly an enforcement thing.
reply
Because corporations are just a group of people.
reply
So corporations can go to prison then? Or do you think some groups of people should get a free liability shield without any restrictions that come with it?
reply
If it's "people all the way down", why do companies pay so much less tax?
reply
What a load of crap. Your liberty to swing your fist ends where my nose begins. What's "triggering" is when it hits my nose.
reply
That's exactly how it will go. Few controlling everything, and a slip might make you not able to live.
reply
Just to dispel some Brazil myths:

1) +95% of the population live on the coast very far away from the Amazon. Most of the population has not been there. Most of the coast has a very different jungle biome called Mata Atlantica and the countryside close to the coast is not that different from temperate forest of Europe. That is what most all Brazilians are used to. There is a significant population in the arid northeast though and the cold south as well (which is even more similar to europe).

2) Manaus is the biggest city in the Amazon and it is huge developed place (and has been for decades). You are not in the middle of the jungle if you land in the airport. The countryside around the city is jungle though.

3) Brazilian people do not necessarily like or are used to tacos and spicy food. Mexico is _really_ far away from Brazil.

reply
That was only 3 myths. Hardly a brazilian
reply
Not even a gorillion
reply
I would not be offended by the blood donation thing. They generalize based on administrative regions (Amazonas in this case) and not whether you visited a big developed city or not.

I had a similar blood donation issue for visiting a particular island in the Philippines, and could not donate for 4 months.

reply
It is funny there is no similar treatment about TBE (tick disease) which is predominantly an European disease and very dangerous...

https://en.wikipedia.org/wiki/Tick-borne_encephalitis

reply
I'm sitting here chuckling because you felt the need to post this.

Your points are valid. And there probably are plenty of Americans who needed the correction. But still.

reply
I have a german last name, do you know how often people outside Brazil act weird when they learn I am Brazilian?

My grandparents came to Brazil right after WW1 way before the Nazis came to power. High ranking Nazis fled to south america because there were a lot of germans living there already. Nearly all german people who moved to south america did it way before WW2.

I just run into this stuff a lot living in Europe.

reply
Honestly at this point it is usually the Europeans that need this (I have been asked if Chile has good tacos from a European). At least in my experience, most USians (in spanish Americans means everyone in the hemisphere) now know more about South America than the average European.

(Which is to be expected, proximity and all)

reply
> If Google wanted to sell a product to the airlines that offered to keep annoying people like me from purchasing flights, they could do that with that email chain. I'm skeptical it'll be wiped correctly. Isn't my poor writing style basically my signature?

The OP article is quite poor in terms of information provided, but the buyer (Google) had to explicitly agree not to attempt to re-identify users. https://www.axios.com/2026/08/17/google-spirit-airlines-bank...

reply
I'd be amused if a sub-sub-agent organically decided to do it anyway - even if just for a notable figure that an LLM can identify with its weights alone. What are the controls? Who's going to keep Google accountable? Hah.
reply
I know Meta it's not Google, but it's worth remembering that these promises haven't had a great measure of success in the past:

> Facebook has been fined €110m (£94m) by the EU for providing misleading information about its 2014 takeover of WhatsApp. (...) When Facebook took over the WhatsApp messaging service in 2014, it told the commission it would not be able to match user accounts on both platforms, but went on to do exactly that.

https://www.theguardian.com/business/2017/may/18/facebook-fi...

reply
So what happened to the sloth??? Don't bury the lead, man!
reply
The sloth was returned to his owner and I did tip him. That kid is probably still prowling the Amazon (as an adult now), looking for sucker tourists like me.
reply
You probably should have taken the kid to small claims, that was extortion
reply
Great way to end up on the no-sloth list
reply
deleted
reply
On a list sold out later to a most vicious data broker after their boat-sloth enterprise went out of business.
reply
Should have kept the sloth.
reply
your personal site SSL cert expired 10 days ago btw
reply
I love the irony of you checking them out for more information in response to a comment of them being worried about who reads their data. Nothing wrong with it, just make me chuckle
reply
There's something about circles of control in this, that makes the difference. If I publish information about myself, that's about me, and it's in my control.

If someone else shares information about me, without my consent, and someone uses that to nose in on me, that feels creepy and problematic.

reply
If you find that concerning, I recommend asking Claude or Codex to analyze all your HN comments and build a profile of you (I recommend that to everyone, not trying to single you out btw.) It takes about 20 minutes. It was eye opening and somewhat unsettling how accurate it was when I ran it on my own data. Even worse, there’s NO way to delete your old HN comments.
reply
Everybody makes mistakes, it's unfortunate that many people on the internet are psycho and won't let the past be the past...
reply
Suckers pay companies for expensive SSL monitoring products, smart people just post to HN.
reply
Doh, thanks!
reply
UptimeKuma is self-hosted and can monitor SSL expiry...
reply
The article directly addresses this concern:

"If you’ve flown Spirit and worry that Google will soon know about a testy conversation you had with the airline’s call center, you’re being told not to worry. The court filing says the data was deidentified before being put on sale and Google has promised to scrub any PII it finds in the trove."

reply
unfortunately "de-identified" data is typically re-identified quite trivially. so i guess we just hope google keeps its promise, and is competent in its scrubbing.
reply
Explicitly trying to re-identify data that has been de-identified is typically a fireable offence at FAANG.

Accidentally making a machine learning system that happens to (potentially) do it is a different matter.

reply
> Google has promised to

This part is worrying.

reply
Well, it also says that the data was already scrubbed. Arguments have been made that this is insufficient.
reply
See the last 3 sentences of GP's post
reply
I have a bridge to sell you.
reply
This is a fascinating story. Thanks for posting it.

That email you accidentally received really bothers me. I don't understand why a CS rep would get this invested to the point of wanting to cause you real harm. They're not the airline. The psychology is fascinating. There are people out there who feel like a mild short-term inconvenience to them where they have no stakes somehow justifies life-changing harm is kinda frightening, honestly.

I'm reminded of the Yahoo search data fiasco that was allegedly anonymized. Turns out, it wasn't so anonymous [1]. For one thing, people tend ed to search their home address. Whoops.

You mention writing style. We already have LLMs quite capable of copying a writing style. It's a natural extension to say we can fingerprint writing style too.

But here's another aspect. Imagine you're in a relationship with someone and you somehow fingerprint their personal data with a company. For example, you use their Netflix to like 5 very obscure movies, to the point where it's likely unique. Now imagine that Netflix's data gets released in an "anonymized" form and you can now find it based on those obscure likes. I can imagine many scenarios like this. And there's no text involved here at all.

[1]: https://www.vice.com/en/article/yahoos-gigantic-anonymized-u...

reply
I don't understand why a CS rep would get this invested to the point of wanting to cause you real harm.

Two possibilities come to mind... 1 - The CS rep has been instructed to do this. Scary, but corporate leaders can be assholes and wield lots of power within their orgs, so doesn't seem completely unlikely to me.

2 - The CS was just a dick.

Frankly, given the behavior of various SuperMegaCorps over the past few decades, I'm going with #1.

reply
And this is why data protection laws, like the (imperfect) EU ones that are so lamented here on HN, are necessary.
reply
That's because they're seemingly perfunctory. What's worse than no law is a bad one that doesn't do anything but make you feel like something is actually being done.
reply
> they could do that with that email chain

Now think about all the Gmail data Google has.

reply
This is why I get bad vibes any time I hit a cloudflare interstitial page. If you ever piss them off it would be trivial to cut you off from most of the internet.
reply
Did you end up getting more than $100?
reply
Well at least you didn't land in the middle of nowhere. Nokia had the worlds largest cell phone factory there back in the day.
reply
Manny retail industries already share lists of "troublesome" customers (trouble = anything from too many returns to lawsuit-happy to friendly fraud). Not sure this is a new concern..
reply
I think you might have missed the deidentification piece?
reply
Not trying to be snarky, and perhaps it wasn't well stated, but the last paragraph I said I'm concerned about identification via my writing style. If they have my emails, they would have my writing style. It doesn't have to be tied to PII there, they can cross reference it with my blog. I'm speculating because I read that you can identify people by a few sentences of their writing.

"Deidentification" seems really murky and imprecise at best.

reply
Reidentification via writing style is definitely possible, and I doubt the vendor will modify things in a way sufficient to handle that.

But I think this is a place where we should apply bounded distrust: there are lots of places where we should distrust Google, but reidentifying people in an explicitly deidentified dataset isn't one of them.

reply
Based on their trackrecord, That's definitely a concern. I don't really understand on which basis you conclude 'isn't one of them' . 'Don't be evil' ? :-P
reply
You have to trust that this really "deidentifies". Time and time again it was shown, that the measures taken were not enough to anonymize.

E.g. the parent wrote that he fears, he could be identified by his writing style, which is totally plausible. How would you "deidentify" this?

reply
Even if they follow to the letter a deidentification process, Google and Meta have so much data about individuals that re-identification shouldn't be very hard for the majority of airline passengers' data they put their hands on.

Of course, takes a lot more effort than not doing proper deindetification in the first place but if they wanted to appear like caring about data privacy they still have enough data points to correlate the sets later on (and/or over time).

reply
Even before LLMs there were multiple papers written about ways to to reidentify people with ML and other statistical analysis. It is probably now even more trivial especially if you are Google.
reply
No such animal.
reply
I have a bridge for sale, hardly seen use, pay me ${money} and you can collect it in New York City. Interested?
reply
> But, this is the kind of information I'm worried about when a vendor sells my data

Don't worry. Spirit probably lost all of the emails from the customers (or they were devnulled) and 90% of the data is probably autoresponder messages promising the company would respond.

The other 10% was probably the meme collection of the executive management team.

reply