Theoretically, if the file is linked only on a secured page, it shouldn't be discovered by bots, but the file is not in a read-protected state and will be served if the path to it is specified. Really there's no guarantee that files under /Data can't be found.
The only way to truly secure files within mojoPortal is to store them within an instance of the Shared Files module.