Where to store publicly-accessible files

I think that would depend how you’ve made your site private?

I’ve used this plugin to set sites to private
https://wordpress.org/plugins/jonradio-private-site/

It also has settings to exclude any URLs from being set to private.

There are a bunch of other plugins that do similar thins.