digitalocean.com stored your password in plaintext!!!
So to directly address your concern, you can't download the keypair at any point in time, it's just a one time thing. To me that seems much more secure than emailing out a root password and enabling password authentication by default.
AWS cannot view or provide you your private key at any time - once you click 'ok' on that javascript window, that private key is gone for good.