<?xml version="1.0" encoding="UTF-8"?>
<!--
  Hand-maintained on purpose: this lists ONLY the public marketing pages, which
  is the same short set as PUBLIC_PAGES in middleware.ts. Generating it from the
  build would sweep in /dashboard, /monitor, /promo, /mockups/* and the rest of
  the password-gated pages, which is exactly what must not be advertised.
  If you add a page to PUBLIC_PAGES, add it here too.
-->
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
  <url><loc>https://biscuitweb.co.uk/</loc><priority>1.0</priority></url>
  <url><loc>https://biscuitweb.co.uk/portfolio</loc><priority>0.9</priority></url>
  <url><loc>https://biscuitweb.co.uk/how-it-works</loc><priority>0.8</priority></url>
  <url><loc>https://biscuitweb.co.uk/about</loc><priority>0.7</priority></url>
  <url><loc>https://biscuitweb.co.uk/faq</loc><priority>0.6</priority></url>
  <url><loc>https://biscuitweb.co.uk/contact</loc><priority>0.8</priority></url>
  <url><loc>https://biscuitweb.co.uk/legal/terms</loc><priority>0.2</priority></url>
  <url><loc>https://biscuitweb.co.uk/legal/privacy</loc><priority>0.2</priority></url>
  <url><loc>https://biscuitweb.co.uk/legal/cookies</loc><priority>0.2</priority></url>
  <!-- /ie/* omitted on purpose: still behind the site password. See the note
       in middleware.ts PUBLIC_PAGES. -->
</urlset>
