Your Company's Mail and Chat Are a Record Someone Can Buy

Your Company's Mail and Chat Are a Record Someone Can Buy

Spirit Airlines went bankrupt, and its internal business data went up for auction. Google won with a $10 million bid, outbidding Mercor's $7.5 million, and said it plans to use the data for product development and training its AI models. According to Reuters, the data includes employee emails, Microsoft Teams messages, spreadsheets and calendars, plus marketing, productivity and operations data. It is to be de-identified before the sale completes, and the filing report says it contains no customer information or personally identifiable information.

Today, 8 October 2026, Senator Elizabeth Warren and Representative Steven Horsford led a letter signed by 121 U.S. Senators and Representatives to Google CEO Sundar Pichai and Spirit CEO Dave Davis, raising their “serious concern” about the proposed sale. The members write that it “presents uncharted territory” and, by their count, would involve “approximately 100 million emails, 500 million Microsoft Teams messages, employee records, timecard records, payroll and tax information, and employment contracts.” The sale is still proposed, the letter comes ahead of the next scheduled hearing, and the members want “meaningful, enforceable safeguards.” Whatever the court decides, the interesting part for anyone who runs a business is that the record existed as something sellable at all.

Who owns your work email once the company is gone

Most of us treat work email and chat as a service. From the company's side it is something else: a file that grows every day with everything the staff wrote, sent and attached. When the company fails, that file can be handled like any other asset.

A normal company archive holds:

  • Attachments: contracts, invoices, spreadsheets, and the scanned ID someone sent to HR years ago.
  • Calendars: who met whom, how often, and under what meeting title.
  • An org chart: nobody writes it down, but it falls out of the To and CC lines and the chat channel memberships.
  • HR and payroll threads: offer letters, salary discussions, timecards, sick notes.
  • Chat: the informal layer of half-made decisions and complaints.

De-identification removes names, addresses and other direct identifiers. It does not remove the shape of the operation. A message from “Employee A” to “Employee B” about a shift swap on a given date at a given base still describes a real person's working day, and anyone with outside knowledge can often fill in the gap. EPIC (the Electronic Privacy Information Center) made this point in an amicus brief supporting the flight attendants' union's objection, arguing that “the risk of exposure by inference is greater than ever given recent advances in artificial intelligence.”

While a company is alive, its record is held by the company and by whichever vendor hosts it. When the company stops existing, the people who wrote that record are not the ones deciding what happens to it. The letter puts the gap plainly: “Consumers have more privacy protections than workers, yet Spirit has collected far more private information about its employees than about its customers.”

What actually decides custody

Custody comes down to three questions: whose disk holds the data, who holds the keys, and who else has a copy. With a hosted suite, the answer to all three includes a vendor. When you self-host, the answer is you.

Mail

For mail I run docker-mailserver on a small server. Mailcow and Mailu do the same job and add a web admin panel. With docker-mailserver, once compose.yaml and mailserver.env are filled in, the whole stack starts with one command:

docker compose up -d

The record is a few folders on the host, next to the compose file:

  • ./docker-data/dms/mail-data/ holds every mailbox in Maildir format, one file per message.
  • ./docker-data/dms/config/postfix-accounts.cf holds the accounts and password hashes.
  • ./docker-data/dms/config/opendkim/keys/ (or config/rspamd/dkim/ if you use Rspamd) holds the DKIM private keys that sign your outgoing mail.

On Mailcow the same record lives in the vmail-vol-1 and mysql-vol-1 Docker volumes. Either way, whoever holds the admin login can read every mailbox, so it matters who has it. I wrote up how that works in the mailbox and the master key.

Chat

For chat, Matrix with Synapse is my default replacement for Teams or Slack, and I compared the two in Matrix vs Slack. Rocket.Chat and Mattermost are reasonable choices too. A Synapse stack with PostgreSQL also starts with docker compose up -d, and its record is:

  • The PostgreSQL volume: every message event, room, membership and user account.
  • /data/media_store/: every uploaded file and image.
  • /data/<your.server.name>.signing.key: your server's identity on the Matrix network. Back it up and keep it private.

In end-to-end encrypted rooms the database stores only ciphertext, and the keys live on users' devices.

None of this is magic: it is still data on a disk that can be copied. The difference is that no vendor sits between you and it, so no outside party holds a copy that could be transferred to a buyer. If you want an AI model over your own archive, run it locally too, as I describe in keeping self-hosted AI data local.

Retention: delete what you never needed

This is the part almost nobody sets up. The default on every mail and chat system I have run is to keep everything forever, and nobody notices because disk is cheap. Ten years later the archive holds every salary negotiation and heated thread, doing no work at all.

EPIC's brief argued that letting the sale go ahead “would create perverse incentives for employers to over-collect employee data.” You do not need a view on the case to take the practical lesson for your own servers: data you never kept cannot be sold, leaked or handed over later.

Here is the policy I use for a small team. Ask your accountant how long financial and payroll records must be kept where you are.

  1. Trash and Junk: 30 days.
  2. Inbox and Sent: 3 years.
  3. A Records folder for contracts, invoices, payroll and tax mail: kept for as long as the law requires, then deleted by hand once a year.
  4. Chat messages: 1 year. Uploaded files: deleted after 1 year without access.
  5. Backups: 7 daily, 4 weekly, 12 monthly.

For Trash and Junk, Dovecot can expire mail by itself. In docker-mailserver, add this to docker-data/dms/config/dovecot.cf and restart the container:

namespace inbox {
  mailbox Trash {
    autoexpunge = 30d
  }
  mailbox Junk {
    autoexpunge = 30d
  }
}

For Inbox and Sent, use doveadm from the host's crontab. Run the search first so you see how many messages would go:

# dry run: count messages older than 3 years
docker exec mailserver doveadm search -A mailbox INBOX savedbefore 1095d | wc -l

# crontab: every Sunday at 03:00
0 3 * * 0 docker exec mailserver doveadm expunge -A mailbox INBOX savedbefore 1095d
5 3 * * 0 docker exec mailserver doveadm expunge -A mailbox Sent savedbefore 1095d

The Records folder is untouched because the jobs name only INBOX and Sent. For Synapse, add this to homeserver.yaml:

retention:
  enabled: true
  default_policy:
    max_lifetime: 365d
  purge_jobs:
    - interval: 1d

media_retention:
  local_media_lifetime: 365d
  remote_media_lifetime: 30d

This purges old events from the server. Copies already synced to devices stay there, so tell your team the policy.

Finally, backups. If your backups keep everything forever, your deletion policy is fiction. With restic, run this after each backup:

restic forget --keep-daily 7 --keep-weekly 4 --keep-monthly 12 --prune

Your real retention is the policy plus the age of your oldest backup. With the settings above, deleted mail can survive for up to a year in a monthly snapshot. Know that number.

The honest limits

Self-hosting does not put you above the law. If your company goes bankrupt, the servers are company assets, and a trustee can sell the hardware with the disks inside. If you sell the company, the mail and chat archive goes with it, and the employee records in it still need careful handling.

What you gain is narrower but real. Your data does not sit on a platform that can be asked to hand it over, and you are not renting the record from someone whose interests are not yours. The retention policy is yours, and it actually runs. When you close a side project or a small company on your own terms, deleting the record is a command, not a support ticket.

The costs are also yours:

  • Deliverability: reverse DNS, SPF, DKIM, DMARC and IP reputation. Many residential IP ranges are blocked by large providers, so you may need a smarthost for outgoing mail.
  • Spam: filters need tuning in the first weeks.
  • Patching: mail servers and Synapse ship security fixes regularly, and someone has to pull the new images.
  • Backups: they only count if you have restored from one at least once.

If none of that appeals, a hosted provider with a clear data processing agreement and a working export path is a fair choice, as long as it is a decision rather than a default.

Where I land

I run my own mail and chat because I want the record of my work on a disk I can point at, with keys I hold and a deletion schedule that actually runs. If you would rather have someone set this up and harden it for you, have a look at the services page.

Fiverr: hiteshsaini459 · Upwork: hiteshsaini25