GrapheneOS
Thank you for your reply, however, I have carefully studied the FAQ section from your site. Yes, I know about the problems of the gecko engine and Firefox in general. But I also don't think it's a good idea to let all my traffic (including mail and messengers) through a third-party VPN provider, no matter how reliable it is. Yes, of course, you can configure a VPN application and run only the browser through it, but what's the point if there is a wonderful solution for this - a true https proxy? Why do we need userspace-level applications (wireguard), which will also work with application exceptions (in terms traffic routing) if all the work can be transferred to a remote proxy server? Yes, we have an IKEv2 at the seystemspace level working. It is not configurable and wraps the traffic entirely, as well as the system does not understand the carrier in this case (with this configuration, the system cannot determine whether it is on wifi or on mobile data). This is also critical for me.
So, my solution - working with firefox and foxyproxy, with noScript, with uBlock, and less tabs (1-3). And clear all data 4-5 times during day.