The Bitcoin address where you receive BTC is derived from the public key with more hashings to simplify it even further. So, the sequence of operations will be this:
private key -> public key -> address where you receive BTC
All these procedures are absolutely one-directional.
You are right, but there is a small correction to the way you simplify this explanation, Bitcoin are recieved on the address, but this address is not directly from the public key, they are derived from the public key hash which is why we have different types of Bitcoin locking scripts. Among them, we have the old p2pk, p2pkh, p2sh and we have the SegWit scripts. It is these pubkey hashes that are encoded into the address, not the public key.
That total incapacity for recovery only exists if there is personal custody. If you lose your password to an account at an exchange house like Binance or Coinbase, it's a completely different scenario, because those exchange houses have your private key for you, that's what custody means. So, you can recover your account using traditional account recovery methods.
The centralised exchanges are custodial services, they help you manage your coins. You give them the coin, and they give you a platform where you keep records of transactions but most of them are not reliable, they have failed their customers, most of the exchanges have lost funds to hacks, and they don't speak up. We have some that have been bankrupt for years now and are still paying creditors. If you want to avoid these nightmares, use a custodial wallet.