>Is IPFS any more secure than plain torrents for this?
No. The other side still needs tlo know the address in which to send requested data back.
>I assume that IP addresses are exposed when you download data from peers
YES, and not only that but IPFS also reports internal addressing as well.
>so couldn't a person/company pin content and see who downloads it?
YES there's a command in ipfs that reports all peers that are sharing $HASH. It's easily determined and easily findable.
>I guess in general I'm wondering how much info ipfs exposes about you.
Try running ipfs locally and playing with the commandline tool. It's pretty clearcut how it works and what information you're sharing.