@utouchuser You could make webapp click packages instead, for web sites you use frequently. This way, each web site will be run in its own confined browser instance with its own separate profile. This way, malicious javascript could not read data for other sites you use, for example, since the config would be a different browser profile on disk, in a different directory, which cannot be accessed.