Control panel > User accounts > Create a new account
Password protect the new account.
Yeah but any account can pretty much navigate to /Users/[account] and access all the files.
No. not ANY account. Only those with admin privileges. Even with admin privileges no one else can read the file if is is encrypted by the account holder.
You're right, I didn't realize my default account was admin. Now, this option is really good enough for me, but if I put in my admin password and get in there once, that permission will be added to my user account. How can I remove this later?