As for everything else: trust, possibly enhanced by the fear of consequences for the other party.
How do we know if random internet service sells our email / password pair? They probably store the hashed password because it's easier (libraries) than writing their own code, but they get it as cleartext every time we type it in.