<?xml version="1.0" encoding="UTF-8"?>
<!--
  Only the public pages. Every app route is behind login and returns the same
  empty shell, so listing them would waste crawl budget and index nothing.

  This exists because Google's OAuth branding check reads its own index of the
  home page rather than fetching it: an uncrawled host reads as a blank page and
  fails with "your home page does not explain the purpose of your app".
-->
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
    <url>
        <loc>https://provider.employeewellnesshub.app/</loc>
        <changefreq>monthly</changefreq>
        <priority>1.0</priority>
    </url>
    <url>
        <loc>https://provider.employeewellnesshub.app/privacy-policy</loc>
        <changefreq>yearly</changefreq>
        <priority>0.5</priority>
    </url>
    <url>
        <loc>https://provider.employeewellnesshub.app/terms-of-service</loc>
        <changefreq>yearly</changefreq>
        <priority>0.5</priority>
    </url>
</urlset>
