I'm assuming you are using unique passwords per application.
Yes, absolutely, and I only use the web, no other kind of client, no apps etc.
Ever used a friends computer to sign in?
Don't use other computers besides this one for Twitter. The password is very long, generated, so impossible to guess and I have never moved it to another machine.
Obviously other vectors are possible, but in the absence of knowledge it is likely appropriate to react in a secure by default way.
Out of curiosity which OS and browser?
No Javascript unless expressly authorized making some kind of drive-by browser attack quite unlikely.
I'm assuming you are using unique passwords per application.