Session management
SendWhale tracks active sessions across the devices where you are signed in. To review your sessions:- Go to Account → Security.
- View the list of active sessions, including device type and approximate location.
- Click Revoke next to any session you do not recognize or no longer need.
API key and access token security
API keys and access tokens grant programmatic access to your workspace. Treat them with the same care as passwords.Store keys safely
Always store API keys and access tokens in environment variables or a secrets manager — never hard-code them directly in source code.
Never commit to repositories
Never commit keys to a public or private repository. Use
.gitignore and secret-scanning tools to prevent accidental exposure.Rotate exposed keys
If a key may have been exposed — through a public commit, a leaked log file, or any other means — rotate it immediately by generating a new key and revoking the old one.
Revoke unused keys
Revoke API keys you are no longer using from Workspace Settings → API Keys. Dormant credentials are an unnecessary risk.
Principle of least privilege
Use the lowest-permission credential type that each use case actually requires:- Brand read key — use this for reading brand context via the Brand Context API. It does not grant write access to campaigns or contacts.
- Campaign API key — use this for campaign operations such as creating drafts or updating templates. Do not use it in contexts where read-only access is sufficient.
Private file attachments
Files you upload to SendWhale — images, attachments, and assets — are stored privately. They are not publicly accessible unless you explicitly use them in a published campaign or hosted page. Do not upload sensitive documents or confidential files to your SendWhale image library.Backup, restore, and delivery behavior depend on verified operator configuration. SendWhale does not make specific SLA or data-retention guarantees in its documentation.