<?xml version="1.0" encoding="UTF-8"?>
<!--
  Only paths that render distinct content belong here. vercel.json rewrites
  every unmatched path to index.html, so an invented URL returns HTTP 200 with
  the landing page instead of a 404 — a soft 404 that duplicates the homepage
  rather than an obvious dead link. src/main.tsx is the source of truth for
  which roots render what; publicRouteCoverage.test.ts checks this file against
  it, so adding a URL here that main.tsx does not serve fails the suite.
-->
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9"
        xmlns:xhtml="http://www.w3.org/1999/xhtml"
        xmlns:mobile="http://www.google.com/schemas/sitemap-mobile/1.0"
        xmlns:image="http://www.google.com/schemas/sitemap-image/1.1"
        xmlns:video="http://www.google.com/schemas/sitemap-video/1.1">

  <!-- Homepage — marketing landing page -->
  <url>
    <loc>https://getbobao.com/</loc>
    <lastmod>2026-08-18</lastmod>
    <changefreq>weekly</changefreq>
    <priority>1.0</priority>
    <mobile:mobile/>
  </url>

  <!-- Public feature showcase. Renders for a signed-out visitor with no
       location and no backend, which is what makes it worth indexing. -->
  <url>
    <loc>https://getbobao.com/demo</loc>
    <lastmod>2026-08-16</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
    <mobile:mobile/>
  </url>

  <!-- Legal pages. App Store and Play Store require these to be publicly
       reachable, so they are exempt from the returning-user bounce in
       main.tsx and stay indexable. -->
  <url>
    <loc>https://getbobao.com/privacy</loc>
    <lastmod>2026-08-16</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.3</priority>
  </url>

  <url>
    <loc>https://getbobao.com/terms</loc>
    <lastmod>2026-08-16</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.3</priority>
  </url>

  <!-- Static store-listing pages served straight from public/. Not duplicated
       by any SPA route, unlike privacy.html, which is left out because it
       covers the same ground as /privacy. -->
  <url>
    <loc>https://getbobao.com/support.html</loc>
    <lastmod>2026-08-16</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.4</priority>
  </url>

  <url>
    <loc>https://getbobao.com/delete-account.html</loc>
    <lastmod>2026-08-16</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.3</priority>
  </url>

</urlset>
