<?xml version="1.0" encoding="UTF-8"?>
<!--
  iCare Advance sitemap.

  Public, indexable routes ONLY. Every URL below maps to a route in
  client/src/App.tsx that is NOT wrapped in <ProtectedRoute> or <AdminRoute>.

  Deliberately excluded:
    - all /dashboard, /loans, /payments, /documents, /profile, /request,
      /onboarding, /loan/* customer routes (ProtectedRoute)
    - all /admin/* routes (AdminRoute)
    - /forgot-password, /reset-password, /verify-email, /verify-email-change,
      /plaid-oauth — token-bearing or session-bound, must never be indexed
    - the /privacy, /terms, /apply redirect aliases — they 302 to a URL that
      is already listed here, so listing them would duplicate content

  When a public route is added or removed in App.tsx, update this file and
  client/public/robots.txt together.
-->
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">

  <url>
    <loc>https://icareadvance.com/</loc>
    <lastmod>2026-08-18</lastmod>
    <changefreq>weekly</changefreq>
    <priority>1.0</priority>
  </url>

  <url>
    <loc>https://icareadvance.com/register</loc>
    <lastmod>2026-08-18</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.9</priority>
  </url>

  <url>
    <loc>https://icareadvance.com/resources</loc>
    <lastmod>2026-08-18</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
  </url>

  <url>
    <loc>https://icareadvance.com/login</loc>
    <lastmod>2026-08-18</lastmod>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
  </url>

  <url>
    <loc>https://icareadvance.com/legal</loc>
    <lastmod>2026-08-18</lastmod>
    <changefreq>yearly</changefreq>
    <priority>0.4</priority>
  </url>

  <url>
    <loc>https://icareadvance.com/data-retention-policy</loc>
    <lastmod>2026-08-18</lastmod>
    <changefreq>yearly</changefreq>
    <priority>0.3</priority>
  </url>

</urlset>
