However, in 2013 it should be clear that it is no way whatsoever safe to just assume that information flowing through a third party's server will not be stored.
• passwords are stored for a minute, maybe up to two hours
• emails are stored for a few minutes, maybe a few hours
Most clients will poll for emails every few minutes, which means that the storage of the passwords is for all intents; permanent.
I would also hope they're not storing passwords in plaintext. Obviously they need access to the plaintext password to auth with your mail server, but I would hope this is still stored encrypted.
Many emails are signed with DKIM now, which does help with verifiability.
> but I would hope this is still stored encrypted
Encryption is pointless when the keys for decryption are on the same server. Given their hack in 2012, I doubt there's any protection at all.