People in the past have made a replica of the Windows logon screens. Naturally, people have entered their usernames and passwords into it, and the computer didn't log on. However, the program saved all attemps to log on to a text file (getting everyone's ID and passwords) for the er... Naughty boy to retrieve later...
Anyway here's another tip:
You can (Windows XP at least) encrypt your private files using the encryption tool in Windows. The encryption cannot, and will not be broken. But remember to decrypt the files and folders before formatting or transfer the certificate (Algorithm) to floppy first, as you won't be able to decrypt them when you reinstall, unless you have it.