AI Actress Service Requires Mandatory Face Scan and Mood‑Sensing – Privacy Implications
What Happened – The “Talking Tilly” video‑call service (operated by Xicoia Ltd.) now forces every caller to submit a selfie for an automated age check via the Spanish identity‑verification provider Didit. The selfie is not stored, but an approximate age band and reference number are retained. During each call the system also analyses the caller’s facial expression and voice tone to infer emotional state, records and transcribes the conversation, and processes the data through Google’s Gemini model. The service’s privacy policy relies on “legitimate interests” rather than explicit consent for both the age check and mood‑sensing.
Why It Matters for Trust & Control Assurance
- Demonstrates the need for documented lawful‑basis assessments and consent‑management evidence that a continuous control‑assurance program can capture and audit.
- Highlights the importance of monitoring third‑party data‑processing pipelines (Didit, Google Gemini) to ensure they meet your organization’s privacy‑risk thresholds.
- Shows how automated biometric and emotion‑analysis functions can create control gaps that must be mapped, tracked, and evidenced for regulatory scrutiny.
Who Is Affected – Media & entertainment firms using AI‑generated characters, SaaS platforms offering interactive AI avatars, and any end‑users who engage with such services worldwide.
Recommended Actions
- Conduct a privacy impact assessment (PIA) focused on biometric collection, mood‑sensing, and cross‑border data transfers.
- Map the service’s “legitimate interests” claim to your internal consent‑management controls and capture evidence (policy docs, data‑flow diagrams, retention schedules).
- Verify third‑party contracts with Didit and Google for adequate data‑processing clauses and continuous monitoring provisions.
Technical Notes – Age verification uses a selfie analyzed by Didit; no faceprint is stored, but an age band and reference ID are kept. Mood inference runs on‑device video/audio streams, with recordings sent to US providers for transcription and Gemini‑generated responses. Calls are recorded, flagged by an automated classifier for abusive language, and deleted after 24 hours. Source: BleepingComputer