Well solutions like the one above seem like a kludge to me. What happens when you have installed another photo app that doesn't care about the file names? The best way to handle this is to access the device as a different user, but that means each user is going to need their own settings folders etc. The "much wider problem of 'proper' data security" needs to be solved before this can be handle in any reasonable way. At least in my opinion. However how about locking the person you are loaning the phone to out of certain applications? This could be done with a chown that can be reversed with the entering of a password. Not elegant by any means but...