Only as salted hashes using algorithms designed to be slow, like bcrypt or argon2, so stolen databases stay useless. Any system that can email you your old password is storing it wrong. Better yet, modern auth libraries make doing this correctly the default.
Have a question specific to your product?
Share the context and I will reply with a practical next step.