You need to go up enough so that the file can't be browsed to directly from the web. The exact directory depends on how your web server is set up. The concept is that you put it in a directory that can't be accessed directly so you can provide download links that only work to verified users.