Local and remote.
The Poco client runs on your machine: it counts tokens, applies your organization's redaction policy, and installs the editor hooks. The compression itself - and command filtering and document conversion - runs on our server, which is why prompts and commands are transmitted.
Everything Poco sends travels over TLS, authenticated with your account's API key. Nothing is sent anywhere else.