Talking Tilly: The Camera Keeps Analysing After the Age Check

Stephanie Adlam
5 Min Read
A giant camera lens looks back at a caller inside a pink speech bubble.
Talking Tilly analyses the caller’s camera feed and voice during a conversation.

Calling the AI character Tilly Norwood requires more than switching on a webcam. Talking Tilly checks a caller’s age from a selfie before the first conversation, then analyses facial expressions and voice during the call. A September 19 test by journalist Ax Sharma brought those conditions into focus—and found a safety filter that wrongly blocked his recording before a human review released it. [1]

The practical choice comes before the call: are you comfortable giving an entertainment service access to your face, voice and conversation? Xicoia, the operator, describes these processes in its documents. The available evidence concerns disclosed data handling, not a reported breach.

The selfie gate and the conversation are separate

The first gate checks whether the caller is an adult. Xicoia says the selfie goes directly to verification provider Didit; an unclear age estimate can lead to a photo-ID check. The company says it deletes that verification session after receiving the result, keeping limited check data rather than the images or an identification template. [2]

That promise concerns the age check. It does not mean the subsequent conversation leaves no record. Once a call starts, the service processes the camera feed and voice to respond to the caller and infer mood. Its policy says this analysis cannot be disabled for one call, and distinguishes it from identifying a person by a faceprint.

Talking Tilly privacy policy describes camera and mood analysis that cannot be switched off for one call.
The policy separates live mood analysis from call recording and says it cannot be disabled for an individual call. Source: Xicoia, September 22, 2026.

A browser’s camera permission therefore answers only one question: may this site receive video? It does not, by itself, tell you what the service will infer from that video. Here, the description of mood analysis supplies that missing context.

A weather conversation triggered a safety flag

Sharma reported making three calls. One discussion of weather and news was flagged for abusive language, preventing access to its recording. His September 19 update says Xicoia reviewed the call, confirmed a false positive and released the recording. [1]

The result is useful precisely because it is a specific error followed by a correction. It shows that the service’s interpretation can affect what a caller receives. Three calls do not establish how often that happens, and a mistaken safety flag does not demonstrate that mood detection is accurate or inaccurate.

The recording expires before every trace of the call does

The terms describe a 24-hour window for accessing a call recording, followed by deletion, subject to the policy’s stated exceptions. A transcript can remain for up to eight weeks; the privacy policy lists longer retention for unresolved disputes, safety incidents or legal requests. Conversation memory is another category, and callers can request its deletion. [2] [3]

These separate clocks matter. A recording link expiring is not evidence that a transcript or remembered context vanished at the same time. The terms provide [email protected] for memory-deletion requests and warn against sharing sensitive information about yourself or other people. They also prohibit workplace or educational uses such as assessing employees or students.

The broader question—what information is retained and who can access it—also matters in cases such as the ClarityCheck face-image exposure. That was a different incident involving exposed storage; it is not evidence of exposure at Talking Tilly.

For anyone considering a call, decide before submitting the selfie, keep sensitive conversations and other people out of the session, and distinguish ending a call from requesting deletion of stored data. The AI character’s ability to respond naturally is not a promise that the exchange is private or ephemeral.

References

  1. Ax Sharma. “Viral AI actress’ hotline face-scans every caller, watches their mood.” BleepingComputer, September 19, 2026; updated the same day. Original test and follow-up.
  2. Xicoia Ltd. “Privacy Policy.” Talking Tilly, effective September 17, 2026; accessed September 22, 2026. Data processing and retention.
  3. Xicoia Ltd. “Terms of Use.” Talking Tilly, accessed September 22, 2026. Recording, memory and use conditions.
Share This Article
Follow:
Stephanie is our wordsmith, transforming technical research into engaging content that resonates with users. Her expertise in cybercrime prevention and online safety ensures that Gridinsoft's advice is accessible to everyone—whether they’re tech-savvy or not.
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?