Public, and invisible in the IAM policy
Uniform bucket-level access off means per-object ACLs apply alongside IAM, and an ACL grant does not appear in an audit of bindings
{"name":"my-uploads","storageClass":"STANDARD","iamConfiguration":{"uniformBucketLevelAccess":{"enabled":false},"publicAccessPrevention":"inherited"},"versioning":{"enabled":true},"acl":[{"entity":"allUsers","role":"READER"}]}