Why rule order decides everything
A packet walks a chain from the first rule to the last and stops at the first rule that matches with a terminal target such as ACCEPT, DROP or REJECT. Nothing below that rule is ever consulted, which is why two correct-looking rules can produce a firewall that behaves like neither.
-A appends a rule to the end of the chain, after everything already there. -I inserts it at position one, above everything, including the rules the generator emitted before it. Use -A for ordinary service rules. Use -I only when a rule must be evaluated before a baseline rule, for example a block on one abusive address that would otherwise be accepted by a broad allow rule.
The default policies are applied last in the command script on purpose. Setting -P INPUT DROP before the accept rules exist would cut the connection you are working from, so the script builds the chain first and switches the policy at the end.