<?xml version="1.0" encoding="UTF-8"?>
<!-- lastmod must track the page's real last content change. Frozen dates are
     worse than no dates: a crawler that learns lastmod is unreliable stops
     using it, and the pages that DID change lose the signal along with the
     ones that didn't. Three of the four important pages had drifted 10 to 13
     days behind the files themselves.

     Stamp it from the file. `python3 build-sitemap.py` rewrites every lastmod
     from the mtime of the page it points at, and running it is part of
     publishing — see deploy/deploy.sh.

     changefreq and priority are gone. Google has said for years that it
     ignores both, and a hand-maintained number nobody reads is one more thing
     that can be wrong. -->
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
  <!-- Company -->
  <url>
    <loc>https://nuaj.com/</loc>
    <lastmod>2026-08-18</lastmod>
  </url>

  <!-- Products -->
  <url>
    <loc>https://nuaj.com/nuajprotect</loc>
    <lastmod>2026-08-18</lastmod>
  </url>
  <url>
    <loc>https://nuaj.com/nuajlens</loc>
    <lastmod>2026-08-18</lastmod>
  </url>
  <url>
    <loc>https://nuaj.com/nexaplane</loc>
    <lastmod>2026-08-18</lastmod>
  </url>

  <!-- Legal and security. They must be indexable: the consent banner and every
       footer point at /privacy, security.txt points at /security, and a policy
       that cannot be found reads as one that does not exist. -->
  <url>
    <loc>https://nuaj.com/privacy</loc>
    <lastmod>2026-08-18</lastmod>
  </url>
  <url>
    <loc>https://nuaj.com/terms</loc>
    <lastmod>2026-08-18</lastmod>
  </url>
  <url>
    <loc>https://nuaj.com/dpa</loc>
    <lastmod>2026-08-18</lastmod>
  </url>
  <url>
    <loc>https://nuaj.com/aup</loc>
    <lastmod>2026-08-18</lastmod>
  </url>
  <url>
    <loc>https://nuaj.com/eula-nuajlens</loc>
    <lastmod>2026-08-18</lastmod>
  </url>
  <url>
    <loc>https://nuaj.com/eula-nexaplane</loc>
    <lastmod>2026-08-18</lastmod>
  </url>
  <url>
    <loc>https://nuaj.com/security</loc>
    <lastmod>2026-08-18</lastmod>
  </url>

  <!-- Not listed, on purpose:

       /404 — an error page must never be a search result. It is noindex too.

       /lp/* — the three campaign pages restate the NuajProtect page's content
       for a specific ad audience, so indexing them would put our own primary
       SEO page in competition with three near-duplicates. They carry noindex.
       Paid traffic is unaffected: ads link to them directly and never rely on
       the index.

       /nuajlens/licence — retired 2026-08. It was a second, differently-worded
       copy of the NuajLens EULA; the generated /eula-nuajlens is the one the
       product ships, and the old path 301s to it. -->
</urlset>
