<?xml version="1.0" encoding="UTF-8"?>
<!--
  Public, indexable pages only.

  These are real URLs since the web app moved to BrowserRouter: nginx answers
  any non-file path with the shell (docker/postiq-web.conf), so /privacy is a
  document a crawler can request, not a fragment of "/". While the app ran
  under HashRouter this file listed the root alone, because "#/privacy" is the
  same document as "/" to every crawler.

  Deliberately absent: /login, /auth/callback, /invite/:token and everything
  behind sign-in. They are either private, single-use, or a redirect — nothing
  a search result should ever point at.
-->
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
  <url>
    <loc>https://postiq.omicron-ailabs.com/</loc>
    <changefreq>weekly</changefreq>
    <priority>1.0</priority>
  </url>
  <url>
    <loc>https://postiq.omicron-ailabs.com/privacy</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://postiq.omicron-ailabs.com/terms</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://postiq.omicron-ailabs.com/dpa</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
  </url>
</urlset>
