Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Sep 21, 2026 · 8 min read

Tilly Norwood's AI Hotline Scans Your Face and Mood

Talking Tilly, the video call hotline for the viral AI actress, sends a selfie to a Spanish age check provider before your first call, then infers your emotional state from your face and voice on every call after that. Xicoia Ltd, the UK company behind it, says the legal basis for both is legitimate interests. The service closes on 27 September 2026.

Tilly Norwood is a synthetic actress who spent 2026 being argued about by Hollywood. Her operators built her a phone line. To use it you hold your face up to a camera for a stranger's algorithm, and then keep it there while a second algorithm decides whether you sound happy. Neither step asks for your consent in the legal sense of the word, and that is the part worth reading twice.

Key Takeaways

  • Xicoia Ltd, company number 16248273 in England and Wales, runs Talking Tilly and names itself the data controller in the service privacy policy.
  • Before a first call, a selfie goes from the caller's device to Didit, a Spain based age check provider whose own documentation reports a mean absolute error of 3.5 years.
  • The policy says the call analysis infers your likely emotional state from your facial expression and tone of voice, and cannot be switched off for an individual call.
  • Xicoia cites legitimate interests, not consent, as the legal basis for both the age check and the mood inference, which removes the opt in step a consent basis would require.
  • The ICO's biometric data guidance says in writing that it does not cover biometric classification or categorisation systems, which is exactly the category mood inference falls into.

What Is Talking Tilly?

Talking Tilly is a paid video call service for live conversation with Tilly Norwood, the AI generated actress created by Eline van der Velden. The terms give new users five free minutes, then paid bundles capped at 35 purchased minutes per person. BleepingComputer, which first reported the privacy terms, puts those bundles at 99p for five minutes, £13 for 15 and £22 for 30.

The character is not doing the talking on her own. Xicoia names Tavus as the conversational video platform and Google as a Tavus sub processor supplying the Gemini language model. A call therefore routes your face, your voice and a transcript through a chain of processors, most of them in the United States.

The terms set a hard end: 11:59 PM Pacific Daylight Time on Sunday, 27 September 2026. The hotline is a six day story at the point of writing. The practices it normalised will outlive it.

What Does the Age Check Actually Do?

It estimates your age from a selfie, on a third party's infrastructure, and keeps a small record of the verdict rather than the image. The policy is specific: "Before your first call we check your age using an automated age check provided by Didit, our age-check provider," and "You take the selfie on Didit's own page, and the image goes from your device straight to Didit; we never receive it."

Xicoia also says "no faceprint or other biometric template is kept," and that what survives is narrow: "we keep only the result of the check (passed or not), which method decided it, an approximate age band, the date and a reference number." That is a better retention posture than most age gates on the open web.

Accuracy is the softer spot. Didit's own age estimation documentation publishes a mean absolute error of 3.5 years. Against an 18 threshold, an average error of that size means a real population of 16 and 17 year olds reads as adult and a real population of adults in their early twenties gets pushed to the ID upload fallback. The same arithmetic shows up whenever a regulator reaches for face based age assurance, as in the UK push to make Apple verify ages at the device level.

A person at a desk at night holding a phone up for a video call, lit by the screen, with a webcam and ring light beside a laptop

Why Is Legitimate Interests the Sharpest Detail Here?

Because legitimate interests is the one lawful basis under UK GDPR that does not require the person to agree to anything. The Talking Tilly privacy policy states it twice, once per feature: "Our legal basis for these checks is our legitimate interest in keeping the platform safe" for the age check, and "We rely on our legitimate interest in providing a natural, engaging conversation" for the call analysis.

Pair that with the policy description of the analysis, which "infers your likely emotional state from your facial expression and your tone of voice, so that the character can respond in a way that fits the mood," and the line that follows it: "This processing cannot be switched off for an individual call; if you do not want it, please do not start a call." Take it or leave it is a legitimate position for a company to take. It is not consent, and the policy does not claim it is.

BleepingComputer reports that Xicoia version history shows the legitimate interests choice was made in September 2026, alongside the arrival of the age check. That timing is the interesting bit. A company adding a face scan in the same month it settles on the basis that needs no opt in has, at minimum, thought about which door to walk through.

Is Mood Inference Special Category Data Under UK GDPR?

Probably not, on the ICO's own reading, and that is the uncomfortable answer. The ICO's biometric data guidance puts it plainly: "Not all biometric data is automatically special category biometric data. It only becomes this if you use it to uniquely identify someone." Xicoia says its analysis "is not used to identify or recognise you, it does not create a faceprint, voiceprint or other biometric template." Read the two together and the Article 9 protections that cover fingerprint or facial recognition systems do not obviously attach to a system that reads a face without recognising it.

The gap goes further than most coverage of this story admits. The scope section of that same ICO guidance says, in one sentence, "This guidance does not cover the use of biometric classification or categorisation systems." Inferring an emotional state from a face is classification, not recognition. The UK regulator's flagship biometrics guidance explicitly declines to cover the thing Talking Tilly is doing on every call.

The ICO is not silent on emotion AI in general. In October 2022 it warned organisations about exactly this class of technology, with deputy commissioner Stephen Bonner saying, as TechCrunch reported at the time, that "Developments in the biometrics and emotion AI market are immature. They may not work yet, or indeed ever." Four years on, that warning still has no binding instrument behind it.

The EU Would Have Handled This Differently

Cross the Channel and emotion inference stops being a grey zone, at least in two settings. Article 5(1)(f) of the EU AI Act prohibits the "use of AI systems to infer emotions of a natural person in the areas of workplace and education institutions," subject to narrow medical and safety exceptions, per the text of Article 5.

Note what it does not reach. A paid entertainment call from your sofa is neither a workplace nor a school, so the strictest emotion rule in the world's strictest AI statute would not stop Talking Tilly either. The staged obligations that took effect across the EU in August 2026 put transparency duties on this kind of system rather than a ban. Consumer emotion sensing is uncovered on both sides of the Channel, and Xicoia found the seam.

What This Means If You Point a Camera at a Chatbot

Talking Tilly dies on 27 September 2026, but the template it ships is reusable and cheap. An age gate, a mood sensor, a US model provider and a legitimate interests paragraph is a stack any consumer app can assemble in a sprint. Tutoring apps, customer service video agents and dating products all have a plausible story for why reading your face improves the experience, and the same legal basis is available to all of them.

There is an asymmetry worth naming. Talking Tilly keeps transcripts "for up to 8 weeks from the date of the call," and BleepingComputer reports those transcripts may be reviewed by Xicoia staff and third party partners. The emotional read, meanwhile, is inferred in the moment and used to steer the conversation. You are told the inference happened, but you never see what it concluded about you, and you cannot correct a mood label you were never shown.

Practical things you can actually do:

  • Read the lawful basis line, not the reassurance line. A policy can be honest about retention and still offer no opt out, because legitimate interests needs none.
  • Exercise the right to object. Legitimate interests is the one basis where UK GDPR gives you an explicit objection right, and a controller has to stop unless it shows compelling grounds.
  • Ask about the derived data, not the raw data. Deleting a selfie is cheap to promise. The age band, the reference number and the inferred mood are the parts that persist.
  • Watch the wearable precedent. The same fight over who owns an inference drawn from a body runs through the California and Illinois biometric class actions against Whoop and Oura.

Looking Ahead

Xicoia did something unusual by documenting all of this in a policy a reader can check. Plenty of apps doing worse say less. The problem is not the disclosure. The problem is that disclosure is where accountability stops: the UK's biometric guidance excludes classification systems by its own terms, and the EU's ban stops at the office door.

A regulator will test emotion inference in consumer products eventually. Until then, the only thing standing between a caller and an algorithmic read of their mood is a sentence in a privacy policy telling them not to start the call.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.