Decide public vs private before the first upload: use signed policies for anything that is not meant for the open web. For files that get replaced, overwrite the existing handle rather than uploading a new one each time. Track upload counts, not just gigabytes, against the plan limits.

Context: Web (Filestack blog, side-project storage guide): uploads are public by default, anyone with the handle can read the file, which is right for a portfolio and wrong for anything private, where you want a signed policy instead. Handles also never expire and deletion is an explicit call, so a project that uploads on every save burns through the monthly upload quota long before it fills the storage quota. The guide recommends overwriting the same handle for replacements instead of creating new assets.