WYEA / Privacy

Privacy policy

How WYEA handles information

Effective October 8, 2026 ยท WYEA LLC (Whittle and Ye Engineering Associates), Newport Beach, California

This page covers two things: what this website collects, and how the WYEA platform (the software we run for client firms) treats the information that passes through it, including accounts a firm connects to it such as Dropbox.

This website

The website itself keeps almost nothing. There is no advertising, no analytics script following you between sites, and nothing is sold or shared for marketing.

  • The contact form stores what you type (name, firm, email, message) and the IP address it was sent from, so we can reply and limit spam, and sends it to us by email through our email provider. We keep it until you ask us to delete it.
  • The Brief, an email publication we no longer send, still holds the email addresses of people who signed up and the IP address used. The unsubscribe link in any past issue still works. We keep a record that you unsubscribed so you are never emailed again; to have the address deleted entirely, write to us.
  • Booking a call takes you to Google Calendar's booking page. What you enter there is handled by Google under its own privacy policy, and we receive the booking.
  • Hosting is on Cloudflare, which processes visitor IP addresses as part of serving the site and defending it, as every host does.

The WYEA platform

The platform is software we build and operate for a client firm. That firm's policies, documents, and client information belong to the firm; we process them only to run the firm's own workspace, on the firm's instructions. We do not use a firm's content to train AI models, we do not sell it, and we do not share it with anyone except the service providers needed to run that firm's own system.

Each firm's system runs in its own isolated environment. One firm's information is never visible to another firm.

Connected accounts, including Dropbox

A firm can connect accounts it already uses, for example Dropbox, where its documents live, so the platform can work with documents in place. When someone at a firm connects Dropbox:

  • They approve the connection themselves, on Dropbox's own consent screen, signed in to their own Dropbox account. We never see or ask for their Dropbox password.
  • The connection lets the platform read account and file information, read document contents, save documents back, and read sharing settings: the things a document workspace needs. It is used for nothing else.
  • The firm's Dropbox remains the system of record. The platform reads documents and files finished work back into it; it does not maintain a competing copy of the firm's library. Where the platform retains a copy of specific document versions, it does so to preserve the evidence behind work the firm has already relied on, for that firm alone.
  • The credential Dropbox issues us for the connection is stored encrypted, and is never shown to anyone, including the person who connected.
  • A connection can be removed at any time, either inside the platform or from the security settings of the person's own Dropbox account. Removing it stops the platform's access.

Microsoft SharePoint

A client can connect the SharePoint sites where its documents live. The connection is deliberately narrow:

  • The platform asks Microsoft only for access to sites the client names (Microsoft's Sites.Selected permission), never for the client's whole tenant. Until the client's own administrator assigns a site, that permission reaches nothing.
  • Access is read-only. The platform cannot change, move, or delete a document in SharePoint.
  • When a person connects their own Microsoft account, the platform sees only what that person could already see on the named sites. It also reads their basic profile (name and email) to know who connected.
  • The credential Microsoft issues for the connection is stored encrypted and is never shown to anyone. We never see or ask for a Microsoft password.
  • A person can disconnect inside the platform at any time, and the client's administrator can withdraw the site assignment or the application's consent in Microsoft Entra, which ends all access.

Service providers

We use a small number of infrastructure providers to run our systems: cloud hosting and email delivery. Each receives only what it needs to do its job. We do not sell personal information, and we have not sold it in the preceding twelve months.

California rights

We are a California company. If California privacy law gives you rights over information we hold: access, correction, deletion. Write to us and we will honor them. Note that for a firm's own documents, your request usually belongs with the firm: they are the ones who decide what their system keeps.

Questions

Write to contact@wyea.ai. A person reads it, usually one of the two of us.

If this policy changes in a way that matters, we will change this page and its effective date, and tell affected clients directly.

See it on your own wordings

Mostly standard forms? A shared product may suit you better. We will tell you on the first call.

Prefer to write? We reply within one business day.