<?xml version="1.0" encoding="UTF-8"?>
<!--
  Public routes only. Everything behind ProtectedRoute is deliberately absent:
  a signed-out crawler is bounced to /auth there, so listing them would submit
  URLs that answer with a sign-in screen.

  Also deliberately absent:
    /terms  — a stub whose every card reads "To be written". Submitting thin
              placeholder content is a quality signal working against us.
    /login,
    /start  — functional entry points, not pages with something to rank for.
              They are reachable from every marketing page's nav, so Google
              will find them; they do not need a sitemap entry.

  Host must match the canonical in index.html and the JSON-LD `url` — all
  three are https://www.aloraos.com. If the apex ever wins instead, change
  all three together.
-->
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
  <url>
    <loc>https://www.aloraos.com/</loc>
    <lastmod>2026-08-29</lastmod>
    <changefreq>weekly</changefreq>
    <priority>1.0</priority>
  </url>
  <url>
    <loc>https://www.aloraos.com/privacy</loc>
    <lastmod>2026-08-29</lastmod>
    <changefreq>yearly</changefreq>
    <priority>0.3</priority>
  </url>
  <url>
    <loc>https://www.aloraos.com/contact</loc>
    <lastmod>2026-08-29</lastmod>
    <changefreq>yearly</changefreq>
    <priority>0.3</priority>
  </url>
</urlset>
