Cross Domain calls

Hello everybody,
I'm trying for the first time to use the JSON-RPC APIs. I'm trying to incorporate some zenfolio photoset informations on an external website by launching XHR requests. This requires the ability of making cross-domain requests, and I expected the zenfolio APIs to enable that... but apparently no Access-Control-Allow-Origin is sent.
Am I doing something wrong?
