I'll talk about timing attacks at the end of this.
Here's how it could work, using an RSA-based signature. The age verification service is using RSA with a modulus of N, a public exponent of e, and a private exponent of d.
To produce a signature S for a message M the age verification service computes and returns S = M^d mod N. Someone who wants to verify that S is a signature for M computes S^e mod N and if that equals M then S was a signature for M.
1. Porn site issues a token to User 32323. Let's all this token T.
2. User 32323 picks a random number r that is relatively prime to N. Since r is relatively prime to N, User 32323 can easily compute r' such that r r' = 1 mod N.
3. User 32323 asks the age verification service to sign r^e T.
4. The age verification service, after receiving proof that the user is an adult, which probably involved the user providing government ID that shows their real identity, signs r^e T.
Remember, to sign the age verification service raises the message they are signing to the power of d mod N, which in this gives r^(ed) T^d = r T^d mod N. The age verification service returns r T^d to User 32323.
5. User 32323 can multiply that r T^d by r', giving T^d mod N.
Note that T^d mod N is the signature that the age verification service would have generated if it had been given the token T directly to sign, instead of having been given r^e T.
The net result is that the age verification service has signed T without ever having seen T. They only saw r^e T.
6. User 32323 can return their token T back to the porn site, along with the signature S = T^d mod N, and a note telling the porn site which age verification service was used.
7. The porn site looks up the modulus N and public exponent e for that age verification service, compute S^e mod N and see that this equals T. That tells them that an adult used the age verification service to get T signed, so they allow the account to be created.
If someone is trying to figure out the real identity of User 32323 they might get T and T^d mod N from porn site. And they could get all the messages that the age verification service signed between the time T was issues and the time User 32323 submitted T^d mod N.
But for each message M there will be some r such that r^e T = M, and so any such message could be the right one [1]. You get no information other than whatever you can infer from timing.
Same for someone starting with the age verifications of a particular person and trying to figure out if any of those are for some particular porn site.
I think that age verification would probably only be done at account creation, which would mean much less timing information would be available. The risk of a timing attack could be further reduced by using a high volume verification service so that there are more verifications going on at near the same time.
You would further reduce the risk by adding some delay on your end. Wait until several hours or even a day or two after receiving T from the porn site before you return the signed T to complete your signup.
[1] There is a very small possibility of a T where there is no r that maps it to M. That could happen if T happened to have a factor in common with N. Since the N for an RSA system is constructed by multiplying two large (thousands of bits) together the chances of accidentally hitting such a T are in the 1 in 2^thousands. And no one knows how to deliberately construct such a T without first factoring N.