Bitcoin's keys live on secp256k1, the curve y² = x³ + 7. Its points form a group: you can add two points with a ruler and you can multiply a point by a whole number. That multiplication, k·G, is a one-way street: easy forwards, hopeless backwards. That asymmetry is your private key → public key.
Draw the line through P and Q. It hits the curve once more; reflect that third point across the x-axis and you have R. Doubling uses the tangent at P.
Add a point to its own mirror image and the line through them is vertical, so it never hits the curve a third time. That missing point is the group's zero, the point at infinity.
Bitcoin doesn't use the smooth curve. It uses points over a 256-bit prime, a cloud of ~10⁷⁷ dots. The algebra is identical; only the picture changes.
On secp256k1, one fixed point G generates the whole group. Your private key is just how many times you added G to itself. Counting forward is instant; counting back is the discrete-log problem. (In this page's toy field the demo G traces out a small subgroup; big curves are chosen so that can't happen.)