saturday, september 5, 2026 · the day's ai, attributed published by trilot llc · wyoming
guide · working with ai

What happens to your data when a company goes under

Find the one clause in every vendor contract that decides where your work goes when the company stops existing, and fix what you can while everyone is still solvent.

Published 2026-09-05 · Updated 2026-09-05 · Read 9 min · Reviewed by Rami Steitieh

Verified 2026-09-05 · Rami
on this page · 0 / 0 checked

Your business does not live on your laptop. It lives in a dozen accounts you rent by the month: the shared docs, the invoicing tool, the helpdesk, the years of chat history with a model. You have probably read a privacy policy at some point, and what you read described a company that is still trading. It told you who sees your data on a normal Tuesday.

It did not describe the other day. Companies stop. They get acquired, wound down, or filed into Chapter 11, and at that moment their internal records stop being an operating cost and become an asset a trustee is obliged to sell for whatever it will fetch. There is now a category of buyer for that kind of archive that barely existed five years ago. This guide is about the clause that decides what happens then, where to find it, and what to change while everyone is still solvent. It is not legal advice. If you run something big enough to have in-house counsel, they have already had this argument and you should go ask them how it went.

The archive nobody listed as an asset

In August 2026, Google won a bankruptcy auction for Spirit Airlines’ internal business records with a bid of $10 million [7]. The lot was not the customer database. It was the company’s working exhaust: roughly 100 million emails, about 500 million Microsoft Teams chats, plus calendars, documents, spreadsheets, presentations, marketing material, HR information, project management files, financial databases and audits [7]. Passenger profiles and frequent flyer records were not included [7]. Google said it had acquired “part of an enterprise dataset from Spirit Airlines, which can be helpful in improving our products and AI models”, and that “any data we receive will be rigorously scrubbed of any personally identifiable information by a third party before receipt” [7]. A federal judge still needs to approve the deal; the next-highest bid, from the AI hiring platform Mercor, was $7.5 million [7].

Read past the airline. The thing that sold was the ordinary internal record of a company doing its job for a decade. Every business has one. Yours is the shared drive, the ticket queue, the CRM notes, the Slack channel where you argued about pricing, and the model transcripts where you thought out loud about a client. None of it looks like an asset while you are using it. All of it looks like an asset to someone assembling training data, precisely because it is real, messy, internal and not scraped off the open web.

The bankruptcy code protects consumers, and not all of them

The United States does have a specific rule for this, and it is narrower than most people assume. Section 363 says that where a debtor, in connection with offering a product or a service, disclosed to an individual “a policy prohibiting the transfer of personally identifiable information about individuals to persons that are not affiliated with the debtor”, and that policy was in effect on the date the case commenced, the trustee may not sell that information unless “such sale or such lease is consistent with such policy”, or else “after appointment of a consumer privacy ombudsman in accordance with section 332, and after notice and a hearing, the court approves such sale or such lease”, having given due consideration to the facts and conditions of the sale and found that “no showing was made that such sale or such lease would violate applicable nonbankruptcy law” [1]. Section 332 says the court orders the United States trustee to appoint that ombudsman, a disinterested person, “not later than 7 days before the commencement” of the hearing, and that the ombudsman may provide the court with the debtor’s privacy policy, the potential losses or gains of privacy to consumers, the potential costs or benefits, and the potential alternatives that would mitigate those losses [2].

Three limits sit inside that. The first is that the ombudsman’s job under section 332 is to hand the court information; the judge decides, and nobody is given a veto [2]. The second is the trigger. The protection engages only where the debtor actually disclosed a policy prohibiting transfer, and only where that policy was in force when the case began [1]. A policy that permits transfer, which is what most policies do, engages nothing.

The third limit is the definition. Under section 101(41A), personally identifiable information means information an individual provided “in connection with obtaining a product or a service from the debtor primarily for personal, family, or household purposes”, covering name, home address, electronic contact details, telephone number, social security and credit card numbers, and separately birth date, birthplace and other information that would let someone contact or identify that individual [3]. If you bought your seat as a business, you were not obtaining a service primarily for personal, family or household purposes. Neither was an employee, who did not buy anything at all. So the internal records in the Spirit lot, the HR files and the half-billion staff chats, fall outside that statutory definition [3], while the passenger profiles that would sit squarely inside it were the part kept out of the sale [7].

Your vendors already told you, in the business transfers clause

This is not hidden. Every serious vendor states it plainly, usually in one paragraph you skimmed. OpenAI’s privacy policy, updated 18 May 2026, says: “If we are involved in strategic transactions, reorganization, bankruptcy, receivership, or transition of service to another provider (collectively, a ‘Transaction’), your Personal Data may be disclosed in the diligence process with counterparties and others assisting with the Transaction and transferred to a successor or affiliate as part of that Transaction along with other assets” [5]. Anthropic’s privacy policy, effective 8 July 2026, says: “If Anthropic is involved in a merger, corporate transaction, bankruptcy, or other situation involving the transfer of business assets, Anthropic will receive or disclose your personal data as part of these corporate transactions” [4].

Note what those sentences do. They are not loopholes. They are disclosures, made in advance, that your data travels with the company and is shown to counterparties during diligence. They are also almost impossible to negotiate on a self-serve plan, because you are not signing anything, you are accepting a policy the vendor can and does revise.

Contrast that with the case where a company promised something specific. RadioShack had made “promises not to sell consumers’ information or the company’s mailing lists”, and when its bankruptcy put “information from tens of millions of consumers” on the block, the Federal Trade Commission went to the court and asked for four conditions: that the data go only to an entity “in substantially the same line of business as RadioShack”, that the buyer “agree to be bound by the RadioShack privacy policies that were in place when the consumers’ data was collected”, that the buyer “provide consumers with notice and obtain their affirmative consent” before any materially different use, and that the information “not be sold as a standalone asset, but be bundled with other assets” [6]. The specific promise is what gave a regulator something to hold. A generic business transfers clause gives nobody anything, because it promises nothing.

Deletion is a window, not a switch

The other half of the problem is that your data does not only leave through the front door. A deleted Claude conversation is “removed from your chat history immediately” and “deleted from our back-end storage systems within 30 days” [8]. But if you have left model training enabled, Anthropic “may retain your data in a de-identified format for up to 5 years in our model training pipelines”, and turning training off means it “will not use your previous or new chats or coding sessions for future model training” while your data “will still be included in model training runs that are already in progress, or in models that have been trained” [8]. Where a usage policy violation is detected, inputs and outputs are retained for up to 2 years and trust and safety classification scores for up to 7 [8].

Those are clearly published numbers, and they are worth understanding for what they imply rather than as a complaint. A de-identified copy sitting in a training pipeline is a different object from your account. It is no longer indexed to you, which is the point of de-identifying it, and that is exactly why deleting your account does not reach it and why a change in the company’s corporate form does not either. Whatever gets stripped of your name stops being yours in every practical sense, including the sense in which you could ask for it back. So the decision that matters is not the delete button. It is the setting you left on, on the day you pasted the thing in.

The document that governs your data is probably not the one you read

Account tier changes which contract applies, and people routinely check the wrong one. Anthropic’s privacy policy says it “does not apply to content that we process on behalf of customers of our business offerings, such as our Enterprise accounts”, and points those readers to their customer agreements instead [4]. So the paragraph you just read about mergers and corporate transactions is the consumer paragraph. If you are on a business plan, the sentence that binds your data lives in a document you may never have opened, and if you are on a personal plan, the business protections you have heard about do not reach you.

The practical version for a one-person business is unglamorous. Work out, for each tool that holds anything you would not want sold, which document actually governs your account, then read that document’s transfer and retention clauses rather than the marketing page. Where the difference matters and the price is survivable, move to the tier that comes with a signed agreement, because a signed agreement is a thing you can point at later and a posted policy is a thing the vendor can revise on a Tuesday.

Keep a copy you could actually rebuild from

Everything above is about limiting what a buyer gets. This part is about what you keep. Section 363 governs whether a sale is approved [1]; it says nothing about whether your login still works while the sale is being argued about. Treat continuity as your problem, not the estate’s.

That means exporting on a schedule rather than in a panic, and it means testing the restore rather than the download. An export that produces a folder of files you have never opened is a comfort, not a backup. The number worth knowing is how much of your work exists only inside somebody else’s system at any given moment, which is a function of how often you export and how fast you produce.

calculator
Work that exists only in your vendor's copy
h of work

Average exposure is half the gap between exports, priced in your working hours. gap ÷ 2 × hours ÷ 7. Computed in the page; nothing is sent anywhere.

checklist
Before your vendor's worst quarter
0 of 8 · saved in this browser only

If you are the one holding other people’s data

The mirror of all this is that you are a vendor to somebody. Your client files, your subcontractor agreements, your years of email are an archive too, and if your business ends untidily, the default answer to what happens to it is whatever a court, an executor or an acquirer decides, because nobody wrote down a different answer. The RadioShack sequence shows the shape of the alternative: a specific, written promise about what will never be sold is the thing that gives anyone standing to object later [6]. A clause saying client material is deleted or returned on termination, and is not transferable as an asset, costs you nothing today and is the only version of you that will be in the room on that day.

What still goes wrong

You cannot verify a de-identification you are not party to. Google’s statement that a third party will scrub the Spirit archive before receipt may be entirely accurate, and there is no mechanism by which an affected employee, or you, could check [7]. Assume that “de-identified” is a description of intent and process, not a guarantee you can audit, and make your decisions about what to type accordingly.

Exports are lossy in ways that only show up when you need them. You get the content and not the system: the permissions, the comments, the version history, the automations and the links between things are usually the parts that do not survive, and they are often the parts that took the longest to build. Budget for rebuilding rather than restoring.

And the law here is jurisdictional and unsettled. The sections quoted above are United States bankruptcy law, they turn on definitions written before anyone was buying training corpora, and they do not describe what happens in an acquisition, a solvent wind-down, an estate, or under another country’s insolvency regime. This guide is not for anyone who needs a defensible answer for a regulator or a board. If that is you, the correct move is a lawyer who does insolvency and data protection, not a checklist.

sources
  1. 0111 U.S. Code § 363 — Use, sale, or lease of propertyuscode.house.gov
  2. 0211 U.S. Code § 332 — Consumer privacy ombudsmanuscode.house.gov
  3. 0311 U.S. Code § 101 — Definitions (41A, personally identifiable information)uscode.house.gov
  4. 04Anthropic — Privacy Policyanthropic.com
  5. 05OpenAI — Privacy Policyopenai.com
  6. 06FTC — Requests Bankruptcy Court Take Steps to Protect RadioShack Consumers' Personal Informationftc.gov
  7. 07Axios — Google wins bankruptcy auction for Spirit Airlines emails, chats, documentsaxios.com
  8. 08Anthropic Privacy Center — How long do you store my data?privacy.claude.com
next guide
What MCP is, and what to do when it changes under you
9 min · verified 2026-09-05
related guides