Being able to send passwords back over email and/or view them as an admin does not mean they are stored in the DB in the clear. It is a fairly common practice to strongly encrypt passwords in the DB and decrypt them when it is necessary for admin personnel to be able to use them.