The service’s terms and privacy policy, both effective September 17, say the operator, UK company Xicoia Ltd, uses Spanish identity-verification provider Didit for the check. Xicoia says the selfie goes directly to Didit, that neither party retains the image after the result, and that no faceprint or biometric template is created. But passing the gate is only the beginning of the data processing required to talk to the AI.
BleepingComputer first reported the design after testing the service, which arrived amid attention around Norwood’s appearance on Piers Morgan Uncensored and her role in the proposed AI-generated film Misaligned. The publication found that the product’s privacy terms describe a much broader system than a disposable novelty chatbot: the live call analyzes video, voice, conversation content, safety signals, and prior-session memory.
For Windows users accustomed to granting a webcam or microphone permission once and moving on, the important distinction is simple: camera and microphone access here are not merely transport for a call. They are inputs to ongoing inference.
The check estimates age, then retains a decision record
Xicoia’s published policy says Didit analyzes a selfie to estimate whether the user is 18 or older and to confirm that a live person, rather than a photo or screen replay, is making the request. If the estimate is not clear enough, the service asks for a photo of a government-issued ID and checks the date of birth.
Xicoia says it retains the pass-or-fail result, the verification method, an approximate age band, the date and a reference number. It says it does not retain the selfie, the ID image, the actual date of birth or the ID number. That is a materially narrower record than a service maintaining a reusable identity profile, but it is still enough to connect an account to an age-verification outcome for the life of the product.
The service frames its legal basis for the age check as “legitimate interests,” rather than consent, under UK and EU data-protection rules. In practical terms, users can object to that processing, but cannot use the product without it. The policy is explicit: the check is a condition of access.
For U.S. callers, the policy separately says the pre-scan notice and user agreement are intended to serve as the notice and consent required under applicable state biometric-privacy laws. That acknowledgement is notable because the product markets itself as entertainment, while its onboarding resembles the compliance flow increasingly seen on adult-content and social platforms.
Every live call includes mood inference
The part that deserves closer attention is not the initial age gate. It is what happens after the call connects.
Xicoia says Tilly analyzes the user’s live camera feed and voice to understand objects around them, actions, screen attention, facial expression and vocal tone. The company says the system uses those signals to infer a caller’s likely emotional state so the character can respond in a way that fits the conversation’s mood.
The company insists this is not facial recognition. Its policy says the system does not create or retain faceprints, voiceprints, or other biometric templates, and is not used to uniquely identify callers. Yet the same policy confirms that the service processes facial movements and vocal characteristics in real time to make an assessment about the user’s emotional state.
Those claims can both be true. A system can analyze biometric signals without producing a persistent biometric identity template. For a user deciding whether to join a call, however, the practical boundary is less comforting than the terminology suggests: a service is still examining face and voice data to derive an attribute about the person on screen.
Xicoia says this emotional analysis cannot be individually disabled. The alternatives are to end the call or not start one. The company uses legitimate interests as the legal basis, arguing that mood sensing is part of providing a responsive video conversation.
That is the trade-off hidden behind the phrase “Talking Tilly.” A caller is not simply sending video to an avatar. They are participating in a system designed to read video and audio cues as they speak.
Calls travel through a U.S. AI processing stack
Xicoia’s policy identifies Tavus as the conversational video platform operating the call. Tavus sub-processors listed in the policy include Daily for real-time video infrastructure, Google’s Gemini model for generating character responses, transcription providers such as Deepgram, and cloud or GPU infrastructure including Google Cloud and AWS.
The listed data flow includes live video and audio, conversation content, memory data, session metadata and text for synthesized speech. Xicoia says it has data-processing agreements and transfer safeguards in place for international transfers, but the operational picture is clear: a call made to a UK-branded AI character can involve processing by multiple U.S.-based providers.
The company says conversations, recordings and other content are not used to train AI models, and that Tavus is contractually prohibited from using them to train or improve its models. That restriction matters, particularly at a time when many users reasonably assume that anything spoken to an AI system may become training material.
But “not used for training” is not the same as “not retained” or “not reviewed.” Transcripts can be retained for up to eight weeks for safety, complaints and refund handling. Authorized Xicoia staff and trusted third-party partners may review interactions for quality assurance, safety monitoring, platform improvement, compliance, and legal or regulatory reasons. Aggregate analysis may also be performed before transcripts are deleted.
Call recordings have a shorter stated lifetime: 24 hours, except where Xicoia says it needs to preserve a specific recording for legal requirements, a serious safety incident, or a serious breach of its terms. The company emails callers a recording link during that 24-hour period, and warns that users who download a copy are then responsible for any copies they retain or share.
Safety filtering has already produced a reported false positive
The live service also runs automated safety checks. One detects explicit sexual content on camera and can end a call. Another transcribes speech, scans it against terms and uses an AI classifier to assess whether language amounts to targeted abuse, threats, sexual harassment, or other prohibited conduct.
BleepingComputer reported that one of its three test calls, described as a discussion of weather and news headlines, had its recording withheld after the system allegedly flagged hateful or abusive language. The outlet said no such language had occurred. Xicoia’s terms allow recordings to be withheld or deleted when automated checks identify prohibited, unlawful, or potentially harmful content; withholding the recording does not restore spent minutes.
That episode is a reminder that the product’s moderation system reaches beyond merely refusing a bad prompt. It can determine whether users receive a copy of their own video call after the fact. Xicoia says significant account decisions involve human review and that users can challenge automated decisions, but the policy does not promise that an incorrectly withheld recording will remain available while a challenge is considered. The standard 24-hour deletion clock continues to matter.
For IT administrators, the workplace ban removes one obvious headache. The terms prohibit use in workplace or educational settings, including to assess, monitor, or train employees, job candidates or students. The restriction is sensible given the combination of video, voice, age assessment, emotional inference and recorded transcripts. It also means the service should not be treated as a harmless team-building experiment on managed devices.
The service now ends on September 27, not September 19
There is one important correction in the current paperwork. Earlier search results and versions of the site indicated that Talking Tilly would end at 11:59 p.m. Pacific Time on September 19, 2026. Its current Safety page and Terms now say the service has been extended to September 27.
The deadline is Sunday, September 27, at 11:59 p.m. Pacific time, or 7:59 a.m. British Summer Time on Monday, September 28. All free and purchased calling minutes expire then. The service’s terms say the planned shutdown does not count as an early discontinuation that would trigger a refund for unused purchased minutes.
Xicoia describes Talking Tilly as an experimental entertainment product and reserves the ability to modify, suspend or permanently discontinue it. The product’s limited lifespan does not eliminate the longer retention schedule for some records: session information without conversation content can be retained for up to 18 months, while transcripts have the stated eight-week window and possible exceptions for active disputes or legal matters.
The key takeaway is not that Tilly Norwood secretly performs facial recognition; Xicoia specifically says it does not. It is that the service requires users to accept a stack of age assurance, liveness checking, real-time audiovisual analysis, emotion inference, recording, transcription, safety classification and cross-border processing in exchange for a conversation with a synthetic character.
That may be a reasonable bargain for some adults. It is not a casual webcam permission prompt, and users should decide before the face scan—not after the call starts.