Short answer
Keep the build in Codex Sites while the only people opening it are workspace members. The moment a custom domain, public search traffic or payments become a requirement, the host changes: move the same requirements into a repository and deploy that repository to Cloudflare Pages or Vercel.
GitHub Pages is the lightest option of the three and the most limited. It is the right call when the output is genuinely static and you never want to think about a runtime, and the wrong call as soon as you need server-side code, a database binding or request-time logic.
Storage is the second half of the decision, and it follows the app rather than the host. D1 covers structured records; R2 covers real uploads; a static site needs neither.