Viral AI Actress Service Face-Scans Callers, Tracks Emotions

Tilly Norwood's Talking Tilly video call service scans every caller's face for age verification and monitors emotions before shutdown on September 27.
Table of Contents
    Add a header to begin generating the table of contents

    The “Talking Tilly” video call service operated by viral AI actress Tilly Norwood face-scans every caller for age verification and monitors their moods and emotions during video calls. The service is scheduled to shut down permanently on September 27, following privacy scrutiny of its data collection practices. Bleeping Computer tested the service and reviewed its terms of service and privacy policy on September 19.

    Tilly Norwood’s Viral Glitch and the Launch of Talking Tilly

    Tilly Norwood, an AI-generated actress, went viral after glitching into Chinese during a live appearance on Piers Morgan Uncensored. The incident drew widespread attention to the AI persona and prompted the launch of Talking Tilly, a video call service that allowed users to interact with the AI character in one-on-one video sessions.

    The service positioned itself as an entertainment product, but its privacy practices raised concerns about biometric data collection and behavioral monitoring. Face scanning and emotion tracking are typically used in security, marketing, and research contexts where explicit consent and data retention policies are clearly disclosed. Talking Tilly’s implementation of these technologies in an entertainment setting created ambiguity about how the collected data would be used and retained.

    Talking Tilly Face-Scans Every Caller for 18+ Age Verification

    The Talking Tilly service performs a face scan on every caller before allowing access. The stated purpose of the scan is to verify that the caller is at least 18 years old. Age verification through biometric analysis involves capturing a caller’s facial image, analyzing facial features to estimate age, and either granting or denying access based on the result.

    Face scans for age verification are controversial because they require capturing and processing biometric data — information that is uniquely tied to an individual and cannot be changed if compromised. Unlike passwords or email addresses, biometric data is permanent. If a face scan database is breached, the exposed data can be used for identity theft, surveillance, or re-identification in other contexts.

    The Talking Tilly privacy policy and terms of service do not appear to have provided detailed information about how long face scans are retained, whether they are stored in an identifiable form, or whether they are shared with third parties. These gaps create uncertainty about the scope of data collection and the risks callers accepted when using the service.

    Emotion Monitoring During Video Calls Raises Behavioral Tracking Concerns

    In addition to the initial face scan, Talking Tilly monitors callers’ moods and emotions during video calls. Emotion tracking uses facial expression analysis, voice tone analysis, or other behavioral signals to infer a caller’s emotional state in real time.

    Emotion tracking is used in marketing to measure audience engagement, in mental health applications to monitor patients, and in research to study human behavior. In the Talking Tilly context, the purpose of emotion monitoring is unclear. If the data is used to personalize the AI’s responses, it represents a form of behavioral profiling. If the data is retained and analyzed after the call ends, it could be used to build detailed psychological profiles of callers.

    Privacy Risks of Biometric and Behavioral Data Collection by AI Services

    The combination of face scanning and emotion tracking creates a detailed record of each caller’s identity and psychological state. This data is sensitive because it reveals both who the person is (biometric identity) and how they feel (emotional state). If this data is retained, aggregated, or shared, it could be used for purposes the caller did not anticipate or consent to.

    AI-powered services that collect biometric and behavioral data without clear consent mechanisms or data retention policies pose significant privacy risks. Users may not fully understand what data is being collected, how long it is stored, or whether it will be used for purposes beyond the immediate interaction.

    Regulators in some jurisdictions have begun imposing stricter requirements on biometric data collection. For example, laws such as the Illinois Biometric Information Privacy Act and the European Union’s General Data Protection Regulation require explicit consent, disclosure of retention periods, and secure handling of biometric data. Services that collect biometric data without meeting these requirements may face legal liability.

    Talking Tilly Scheduled to Shut Down September 27

    The Talking Tilly service is set to shut down on September 27. The announcement does not specify whether the shutdown is permanent or whether the service will relaunch under different terms. Users who participated in video calls should consider what data was collected during their interactions and whether they can request deletion.

    Service providers that collect biometric data are typically required to delete that data when the purpose for which it was collected has ended. If Talking Tilly is shutting down, the legal and ethical expectation is that all collected face scans and emotion tracking data should be permanently deleted. Users should verify whether the service’s operators have committed to data deletion as part of the shutdown process.

    Broader Regulatory Implications for AI Entertainment Services

    The Talking Tilly case highlights gaps in the regulation of AI-powered entertainment services. Traditional privacy laws were written before face scanning and emotion tracking became widely accessible technologies. Many jurisdictions do not have clear rules about whether entertainment services can collect biometric data, what disclosures are required, or what penalties apply if data is mishandled.

    The incident may prompt regulators to examine how AI entertainment services collect and use biometric and behavioral data. Services that market themselves as entertainment products may be subject to the same privacy requirements as services in other sectors if they collect sensitive personal information.

    Recommendations for Users Who Participated in Talking Tilly Calls

    Users who participated in Talking Tilly video calls should assume their facial images and emotion data were collected. If the service provided a mechanism to request data deletion, users should submit deletion requests before the September 27 shutdown. If no deletion mechanism was provided, users should contact the service operators directly to request confirmation that their data will be deleted.

    Users should also monitor for signs that their biometric data was retained or misused after the shutdown. This includes watching for unexpected marketing contacts, identity theft attempts, or the appearance of their facial images in contexts they did not authorize.

    The Talking Tilly incident demonstrates the need for users to review privacy policies and terms of service before using AI-powered services, especially those that require video access. Services that request camera permissions, facial recognition, or emotion tracking should be scrutinized for clear explanations of what data is collected, how it is used, and how long it is retained.

    Related Posts