The answer to that depends on what Splunk you are using, and what your configurations look like.
Splunk enterprise (the one you download and install yourself) allows you to configure where the data is stored in the indexes.conf. As long as you have a mount to the location you are storing it, you can have it stored on the cloud, or locally. By default it will store it locally under $SPLUNK_HOME/var/lib/splunk/.
If you are using Splunk Cloud, I hope the answer is clear.
Hope this helps
FYI, i converted your comment to an answer.
It's up to you. There are now four flagship products:
Of these, the first three are software that you install wherever you like. The last one is a cloud service.
To go a step further, the data indexed by Splunk resides within the software and never goes outside unless you configure it to do so.
Great, thank you for your answers 🙂
And I converted your answer to a comment! If you keep discussion in comments, and actual answers as Answer posts, that will make the site work much better for everyone, and allow for people to accurately know which questions have been resolved or not.