How a file gets here

There are two doors, and they behave differently.

DoorWhat happensWhere it lands
Upload in the Documents appYou pick the folderWherever you put it — sensitivity inherited from that folder
Attach on a record (project, invoice, ticket…)The server picks the folder from a registryApps / <App> / <type or record> — you cannot choose, and that is what makes the app-key gate work

Attaching does not create a separate kind of file. It creates a real document in the library plus a pointer from the record. So a file you dragged onto a project is already in Documents — the question was never “does it show up” but “who sees it there”.