Pidgin is one account, assuming passwords are only used once (crazy I know). The browser however has the potential to store all your accounts usernames and passwords.
If the device is rooted a malicious app could simply copy the webview.db and send off your usernames / passwords. Encryption would at least stop anyone who didn't want to brute force a db. I'm not saying it is impossible but that doesn't mean plain text is the right answer.