What's Happening
Tilly Norwood, the AI-generated "actress" behind UK studio Xicoia, went viral this week after glitching mid-interview on Piers Morgan Uncensored and briefly answering in Cantonese. The clip drove traffic to "Talking Tilly," a video-call hotline where anyone can dial in for a live conversation with the AI character before it shuts down for good.
Before a caller reaches Tilly, the service runs a mandatory face scan. An automated selfie check, handled by Spain-based identity verification provider Didit, estimates the caller's age, with a government photo ID upload as fallback when the estimate is unclear. Xicoia says the selfie travels directly from the caller's device to Didit and that neither the selfie nor an uploaded ID is retained afterward, only an approximate age band and a reference number.
The Biometric Data Question
Age verification is not the only thing the camera is doing. Per BleepingComputer's review of the privacy policy, the system continuously analyzes the caller's camera feed and voice tone throughout the call to infer their emotional state, then uses that read to shape the AI character's responses. Mood-sensing cannot be switched off for an individual call; it runs by default for every caller who connects.
That combination, a face scan for age estimation plus real-time emotion inference from face and voice, sits squarely inside the biometric and special-category data processing that GDPR-style frameworks treat with extra scrutiny. Yet both the age check and mood-sensing rely on "legitimate interests" as their legal basis rather than opt-in consent: callers are never asked to affirmatively agree before processing starts, and cannot complete a call without it.
The Fine Print
Calls are recorded and transcribed, then processed by third-party providers, including Google's Gemini model via the conversational-video platform Tavus, based in the US. Recordings are reportedly kept up to 24 hours and transcripts up to eight weeks, reviewed by Xicoia staff and third-party partners. An automated classifier screens transcripts for abusive language and withholds flagged recordings; BleepingComputer found at least one false positive, an ordinary weather chat flagged as hateful content.
Talking Tilly shuts down permanently on September 27, 2026. Free callers get five minutes; paid tiers cap out at 35 purchased minutes per person, and unused minutes are forfeited with no refund. Left unaddressed: what happens to the age bands, reference numbers, transcripts, and stored conversation history already collected once the service goes dark.
Why IT/Security Teams Should Care
Talking Tilly is a novelty hotline, but the pattern is familiar to any team chasing shadow AI inside its own organization. An employee experimenting with a viral consumer AI tool on a work device can trigger biometric-adjacent data collection, under a privacy policy nobody reviewed and a legal basis that assumes consent is not required. Vendor claims that no biometric template is created are also hard for an outside caller, or a security team, to verify independently; they rest entirely on the vendor's own account of its pipeline.
For AI vendor-risk checklists, Talking Tilly is a useful case study: does the tool process camera or voice data server-side, what is the legal basis, how long is data retained, who are the downstream sub-processors, and what is the documented deletion path once the service disappears. A shutdown date is not the same thing as a data-deletion guarantee.