- your DB which stores your data
- your backend which access your data, retrieve it safely, and delivers it without having to know anything about the client it serves.
- your frontend which handle how / when it needs data, which data it needs, how it caches it.
Separation is good, since you can test your API without needing your client, you can test your client code with mock data, you can build different clients (web, native apps, ..) over the same API (and even do not need to build an API if you're using things like graphql)