@ubuntoutou No, unconfined apps can read/write to most any location where the user has filesystem level permissions. However, such apps require manual review, and this is not an appropriate way to implement what you are trying to solve. It would also be an incredible annoyance for yourself, if you wanted to try to rebuild every app you install to be unconfined, every time they get updated.